CVE-2020-10250: Meinbwa Direx-Pro Firmware
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.
Affected products
- Meinbwa Direx-Pro Firmware: version 1.2181 only
Published 2020-03-09. Last modified 2026-06-17.