CVE-2020-36885: Sony Snc-DH120T Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can exploit the vulnerability by sending a crafted POST request with oversized data to the FTP client functionality, potentially causing remote code execution or denial of service.

Affected products

  • Sony Snc-DH120T Firmware: up to and including 1.82.01

Published 2025-12-10. Last modified 2026-06-17.