Critical severity9.8NVD Advisory· Published Sep 22, 2021· Updated Jun 17, 2026
CVE-2019-6288
CVE-2019-6288
Description
Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.
Affected products
3cpe:2.3:o:edge-core:ecs2020_firmware:1.0.0.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:edge-core:ecs2020_firmware:1.0.0.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 1.0.0.0
Patches
Vulnerability mechanics
References
2- twitter.com/r00treaver/status/1232407881464635401nvdExploitThird Party Advisory
- www.edge-core.comnvdVendor Advisory
News mentions
0No linked articles in our index yet.