Unrated severityNVD Advisory· Published Jan 6, 2026· Updated Jan 6, 2026
Secure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/Write
CVE-2020-36909
Description
SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.
Affected products
2- Range: = 3.1.5
- Secure Computing/SnapGear Management Console SG560v5Range: 3.1.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstorm.news/files/id/157939mitreexploit
- www.exploit-db.com/exploits/48556mitreexploit
- www.vulncheck.com/advisories/secure-computing-snapgear-management-console-sg-arbitrary-file-readwritemitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5568.phpmitrethird-party-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/182960mitrevdb-entry
News mentions
0No linked articles in our index yet.