CVE-2020-26549: Aviatrix Controller
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
Affected products
- Aviatrix Controller: version 5.3.1516 only
Published 2020-11-17. Last modified 2026-06-17.