CVE-2020-16259: Winstonprivacy Winston Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.

Affected products

Published 2020-10-28. Last modified 2026-06-17.