CVE-2020-11440: Windriver Vxworks

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.

Affected products

  • Windriver Vxworks: from 5.5, before 7.0 (fixed in 7.0); version 7.0 only

Published 2020-07-23. Last modified 2026-06-17.