CVE-2020-8654 — eonweb
HIGHCVE-2020-8654 is a high-severity (CVSS 8.8) OS Command Injection vulnerability. 6 public exploit references exist, so weaponization risk is real. No vendor fix is recorded yet; mitigation options are listed below.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2020-8654 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 384,534 CVEs with a current EPSS score, this one falls in the ≥ 90% band (highlighted). Counts from FIRST.org, log-scaled.
Description
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.
Affected Products
eyesofnetworkeyesofnetworkResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
by Metasploit · Mar 5, 2020
EyesOfNetwork 5.3 - Remote Code Execution
by Clément Billac · Feb 7, 2020
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2020-8654 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Stop passing untrusted input into the interpreter or shell: call the affected binary with an argument array rather than a composed command string, reject anything outside a strict allowlist of expected values, and run the component under an account that cannot reach beyond the work it legitimately does.
How to detect CVE-2020-8654
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2020-8654 -u https://target- Template
- EyesOfNetwork 5.1-5.3 - SQL Injection/Remote Code Execution
- Severity
- high
- Impact
- Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary SQL queries or remote code on the affected system.
- Remediation
- Upgrade to a patched version of EyesOfNetwork or apply the necessary security patches to mitigate the vulnerabilities.
Template by ProjectDiscovery nuclei-templates (praetorian-thendrickson), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is CVE-2020-8654 in your dependencies?
Find it across , including transitive dependencies.