CVE-2020-37144: Exagate Sysguard 6001

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

Affected products

  • Exagate Sysguard 6001: version 6001 only

Published 2026-02-05. Last modified 2026-06-17.