CVE-2020-25494 is a critical command injection vulnerability affecting Xinuos OpenServer versions 5 and 6. Attackers can execute arbitrary commands by injecting shell metacharacters into the outputform or toclevels parameters of the cgi-bin/printbook script. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, public exploit code exists (EDB-49301), and it has been associated with the FreakOut botnet, indicating active exploitation and significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.7CPE matchmatch criteria | cpe:2.3:a:xinuos:openserver:5.0.7:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:xinuos:openserver:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.