Vulnerability Details CVE-2019-6288
Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.239
EPSS Ranking 95.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-6288
-
cpe:2.3:h:edge-core:ecs2020:-
-
cpe:2.3:o:edge-core:ecs2020_firmware:1.0.0.0