CVE-2020-25195: Hosteng h0-ECOM100 Firmware
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
Affected products
- Hosteng h0-ECOM100 Firmware: up to and including 4.0.348; up to and including 4.1.113; up to and including 5.0.149
- Hosteng h2-ECOM100 Firmware: up to and including 4.0.2148; up to and including 5.0.1043
- Hosteng h4-ECOM100 Firmware: up to and including 4.0.2148
Published 2020-12-15. Last modified 2026-06-17.