High severity7.2NVD Advisory· Published Jul 15, 2020· Updated Jun 17, 2026
CVE-2020-8958
CVE-2020-8958
Description
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Guangzhou/1GE ONUdescription
- Range: 1.9.1-181203 through 2.9.0-181024
- cpe:2.3:o:gpononu:1ge_router_wifi_onu_v2801rw_firmware:*:*:*:*:*:*:*:*Range: >=1.9.1-181203,<=2.9.0-181024
- cpe:2.3:o:gpononu:1ge\+3fe\+wifi_onu_v2804rgw_firmware:*:*:*:*:*:*:*:*Range: >=1.9.1-181203,<=2.9.0-181024
Patches
Vulnerability mechanics
References
3- www.karansaini.com/os-command-injection-v-sol/nvdExploitThird Party Advisory
- www.gpononu.com/dual-mode-onu/1GE-Router-WiFi-ONU.htmlnvdProduct
- www.gpononu.com/gpon-ont/4ge-epon-onu-v2804ew.htmlnvdProduct
News mentions
0No linked articles in our index yet.