Skip to main content
CRITICAL

CVE-2020-16152

CVSS v3

9.8

CRITICAL

EPSS Score

35.5 %

exploit probability, as of 2026-10-05

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Technical details

Published
2021-11-14

Frequently asked questions

What is CVE-2020-16152?

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Is CVE-2020-16152 actively exploited?

Active exploitation of CVE-2020-16152 has not been confirmed. Its EPSS score was 35.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-16152?

CVE-2020-16152 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-16152 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key