Vulnerability record · CVE-2020-11698 · published 17 September 2020
CVE-2020-11698: SpamTitan snmp-x.php community parameter command injection
Titanhq · Spamtitan
Titan SpamTitan 7.07 fails to sanitize the 'community' parameter on snmp-x.php, letting a remote attacker inject commands into snmpd.conf. Because the injected configuration is processed by the SNMP daemon, the flaw escalates from input handling to remote command execution on the server. It matters because the affected host is an email security gateway, a high-value position in the network.
Description
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required, public exploit references, and a very high EPSS score make this an urgent remote code execution risk.
What it is
Titan SpamTitan 7.07 fails to sanitize the 'community' parameter on snmp-x.php, letting a remote attacker inject commands into snmpd.conf. Because the injected configuration is processed by the SNMP daemon, the flaw escalates from input handling to remote command execution on the server. It matters because the affected host is an email security gateway, a high-value position in the network.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the SpamTitan server, gaining full control of the appliance and any mail or credentials it handles.
Attack surface
Reachable over the network via the snmp-x.php page; the CVSS vector shows no privileges and no user interaction required. The description does not state whether the page is exposed pre-authentication, so treat the exact access path as unconfirmed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.73197 (99.4th percentile) and multiple references are tagged Exploit, including Packet Storm and a SensePost writeup, indicating public exploit material exists.
What to do
- Upgrade SpamTitan past 7.07 to a vendor-supported release; confirm the fixed version with TitanHQ since the record does not name one.
- Restrict network access to the SpamTitan administrative interface, including snmp-x.php, to trusted management networks only.
- Disable or block SNMP on the appliance if it is not operationally required, and review snmpd.conf for unauthorized community strings or injected directives.
- Rotate SNMP community strings and any credentials stored on or passing through the appliance.
- Monitor vendor advisories for this product line until a patched version is confirmed.
Detection
- Review snmpd.conf and related SNMP configuration files for unexpected directives, shell metacharacters, or unfamiliar community strings.
- Alert on HTTP requests to snmp-x.php with unusual or encoded characters in the community parameter.
- Monitor for unexpected child processes spawned by the web or SNMP service on the SpamTitan host.
- Audit outbound connections and command execution from the appliance for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/159470/SpamTitan-7.07-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/160809/SpamTitan-7.07-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/felmoltor | Third Party Advisory |
| https://sensepost.com/blog/2020/clash-of-the-spamtitan/ | ExploitThird Party Advisory |
| https://twitter.com/felmoltor | Third Party Advisory |
| https://www.spamtitan.com/ | Vendor Advisory |
| http://packetstormsecurity.com/files/159470/SpamTitan-7.07-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/160809/SpamTitan-7.07-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/felmoltor | Third Party Advisory |
| https://sensepost.com/blog/2020/clash-of-the-spamtitan/ | ExploitThird Party Advisory |
| https://twitter.com/felmoltor | Third Party Advisory |
| https://www.spamtitan.com/ | Vendor Advisory |
Track CVE-2020-11698 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11698), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.