High severity7.5NVD Advisory· Published Jan 6, 2026· Updated Apr 15, 2026
CVE-2020-36907
CVE-2020-36907
Description
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- advisories.ncsc.nl/2020/ncsc-2020-0367.htmlnvd
- community.extremenetworks.com/t5/iq-engine-hive-os-announcements/bg-p/IQ_Engine_Hive_OS_Announcementsnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/181649nvd
- packetstorm.news/files/id/157587nvd
- www.exploit-db.com/exploits/48441nvd
- www.extremenetworks.comnvd
- www.vulncheck.com/advisories/extreme-networks-aerohive-hiveos-x-x-unauthenticated-remote-denial-of-servicenvd
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5566.phpnvd
News mentions
0No linked articles in our index yet.