CVE-2020-36619 is a critical format string vulnerability (CWE-134) in the add_ch function of demod_flex.c within multimon-ng, affecting multimon_ng_project multimon_ng. With a CVSS score of 9.8, it allows unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts over the network. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, upgrading to version 1.2.0 or applying patch e5a51c508ef952e81a6da25b43034dd1ed023c07 is recommended to mitigate this high-risk flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:multimon-ng_project:multimon-ng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.