CVE-2020-36907: Extreme Networks Aerohive Hiveos
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.
Affected products
- Extreme Networks Aerohive Hiveos: up to and including 11.0
Published 2026-01-06. Last modified 2026-06-17.