CVE-2020-28250: Cellinx Nvt Web Server

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi because authentication is on the client side.

Affected products

  • Cellinx Nvt Web Server: version 5.0.0.014b only

Published 2020-11-06. Last modified 2026-06-17.