CVE-2020-10173: Comtrend Vr-3033 Firmware

High severity, CVSS 8.8. EPSS: 77.1% chance of exploitation in the next 30 days.

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

Affected products

  • Comtrend Vr-3033 Firmware: version de11-416ssg-c01_r02.a2pvi042j1.d26m only

Published 2020-03-05. Last modified 2026-06-17.