CVE-2020-17475: Megvii Koala Firmware

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.

Affected products

  • Megvii Koala Firmware: version 2.9.1-c3s only

Published 2020-08-14. Last modified 2026-06-17.