Skip to content
COOEY

EXPOSURES › CVE-2020-25466

CVE-2020-25466

CRITICAL
DETAIL
SourceNVD · cve Published2020-10-23 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-25466 ↗
⚡ RCE SHAME 50/100 rce

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CRMEB's vulnerability was confirmed exploited and added to CISA KEV, indicating critical risk and regulatory scrutiny.
cooey ↗ severe-fallout -0.90
Confirmed critical SSRF flaw enabling remote code execution
"A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code."
cvefeed.io ↗ severe-fallout -0.70
Mirrors CISA KEV, highlighting active exploitation
"Because each KEV entry carries direct evidence of active exploitation, the catalog is one of the highest-signal inputs for risk-based patch management."
www.cvefind.com ↗ severe-fallout -0.50
Cataloged as a known vulnerability for tracking
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
NVD ↗ severe-fallout +0.00
Irrelevant to CRMEB vulnerability
chromereleases.googleblog.com ↗ severe-fallout +0.00
Irrelevant to CRMEB vulnerability
www.enforcementtracker.com ↗ severe-fallout +0.00
Irrelevant to CRMEB vulnerability
NVD ↗ severe-fallout +0.00
Irrelevant to CRMEB vulnerability
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.