CVE-2020-29552: Urve
Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.
An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.
Affected products
- Urve Urve: version 24.03.2020 only
Published 2020-12-23. Last modified 2026-06-17.