CVE-2020-10626: Fazecast Jserialcomm
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.
Affected products
- Fazecast Jserialcomm: up to and including 2.2.2
- Schneider Electric Ecostruxure It Gateway: from 1.5.0.66, up to and including 1.5.2.28; from 1.6.0.39, up to and including 1.6.2.14; version 1.7.0.64 only
Published 2020-05-14. Last modified 2026-06-17.