Vulnerability record · CVE-2020-17456 · published 20 August 2020
CVE-2020-17456: Seowon Intech router system_log.cgi ipAddr command injection RCE
SSeowonintech · Slc 130 Firmware
SEOWON INTECH SLC-130 and SLR-120S series devices pass the ipAddr parameter to system_log.cgi without sanitizing it, allowing OS command injection. Because the endpoint is reachable over the network with no credentials, an unauthenticated attacker can run arbitrary commands on the device.
Description
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a CVSS of 9.8 and public exploit code makes this critical for any exposed device.
What it is
SEOWON INTECH SLC-130 and SLR-120S series devices pass the ipAddr parameter to system_log.cgi without sanitizing it, allowing OS command injection. Because the endpoint is reachable over the network with no credentials, an unauthenticated attacker can run arbitrary commands on the device.
Impact
An attacker gains remote code execution with the privileges of the web service, allowing full control of the router and any traffic or credentials it handles.
Attack surface
Reachable over the network via HTTP requests to the system_log.cgi page, specifically the ipAddr parameter. The CVSS vector shows no privileges and no user interaction required, so it is unauthenticated.
Exploitation
Not listed in CISA KEV, but EPSS is 0.73635 (99.4th percentile) and multiple public references are tagged Exploit, including an unauthenticated RCE exploit, so working exploit code is publicly available.
What to do
- Apply vendor firmware updates for SLC-130 and SLR-120S series devices; if no fix exists, replace or retire the devices.
- Remove or block internet exposure of the device web management interface; restrict access to a trusted management network.
- Place affected devices behind a firewall or reverse proxy that filters requests to system_log.cgi and rejects untrusted ipAddr values.
- Monitor vendor advisories for these end-of-life models and plan hardware replacement where patching is unavailable.
Detection
- Inspect HTTP logs for requests to system_log.cgi with shell metacharacters or command strings in the ipAddr parameter.
- Alert on outbound connections or processes spawned by the device web service, which would indicate command execution.
- Watch for unexpected configuration changes, new admin accounts, or firmware modifications on affected routers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-17456 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17456), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.