CVE-2020-15362: Thingssdk Wifiscanner

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.

Affected products

Published 2020-06-29. Last modified 2026-06-17.