CVE-2020-23161: Pyres TERMOD4 Firmware
Medium severity, CVSS 6.5. EPSS: 2.4% chance of exploitation in the next 30 days.
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.
Affected products
- Pyres TERMOD4 Firmware: before 10.04k (fixed in 10.04k)
Published 2021-01-26. Last modified 2026-06-17.