CVE-2020-37070: Cloudme

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.

Affected products

  • Cloudme Cloudme: version 1.11.2 only

Published 2026-02-03. Last modified 2026-06-17.