CVE-2020-8963
high-risk
Published 2020-02-13
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel or srtime parameter.
Do I need to act?
~
3.3% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (10)
Sr9850 Firmware
Sr9750 Firmware
Sc9705 Firmware
Sr9210 Firmware
Sc9205 Firmware
Sr7110 Firmware
Sc7105 Firmware
T100 Firmware
T300 Firmware
T550 Firmware
Affected Vendors
55
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
7/34 · Low
Exposure
16/34 · Moderate