CVE-2020-16152
CVSS v3
9.8
CRITICAL
EPSS Score
35.5 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Technical details
- Published
- 2021-11-14
Frequently asked questions
What is CVE-2020-16152?
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Is CVE-2020-16152 actively exploited?
Active exploitation of CVE-2020-16152 has not been confirmed. Its EPSS score was 35.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-16152?
CVE-2020-16152 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2020-16152 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).