CVE-2020-13712

A command injection is possible through the user interface, allowing arbitrary command execution as 
the root user. oMG2000 running MGOS 3.15.1 or earlier is affected.

MG90 running MGOS 4.2.1 or earlier is affected.
OS Command Injection
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SWICNA
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H