← Vulnerability feed

Vulnerability record · CVE-2020-8654 · published 7 February 2020

CVE-2020-8654: EyesOfNetwork AutoDiscovery module OS command injection

EEyesofnetwork · Eyesofnetwork

EyesOfNetwork 5.3 lets an authenticated web user with sufficient privileges abuse the AutoDiscovery module to run arbitrary OS commands through the autodiscovery.php target field. Because the flaw is command injection reachable over the network, it gives a privileged user a path to full server compromise.

8.8 CVSS 3.1 High EPSS 91% · top 0.2% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows authenticated remote command execution with high impact and has public exploit code plus a very high EPSS score, though it requires valid privileged credentials.

What it is

EyesOfNetwork 5.3 lets an authenticated web user with sufficient privileges abuse the AutoDiscovery module to run arbitrary OS commands through the autodiscovery.php target field. Because the flaw is command injection reachable over the network, it gives a privileged user a path to full server compromise.

Impact

An attacker with a valid privileged account can execute arbitrary operating system commands on the EyesOfNetwork host, leading to full control of the application server and any data or credentials it holds.

Attack surface

Reached over the network via the /module/module_frame/index.php autodiscovery.php target field. Authentication is required, and the description indicates the user needs sufficient privileges; no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.9118, 99.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Apply the vendor fix for the AutoDiscovery command injection in EyesOfNetwork 5.3 or upgrade to a patched release.
  • Restrict access to the AutoDiscovery module and /module/module_frame/index.php to only trusted administrators.
  • Review and minimize accounts with privileges that allow use of AutoDiscovery.
  • Validate or sanitize the autodiscovery.php target field so it cannot contain shell metacharacters.
  • Monitor and alert on unexpected OS command execution from the web application process.

Detection

  • Inspect web logs for requests to /module/module_frame/index.php with autodiscovery.php and suspicious target parameter values containing shell metacharacters.
  • Monitor for child processes spawned by the web server or PHP process that are unusual for normal application behavior.
  • Alert on outbound connections or command activity originating from the EyesOfNetwork host shortly after AutoDiscovery requests.
  • Audit AutoDiscovery module usage and flag changes or runs by accounts that do not normally use it.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8654 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8657EyesOfNetwork hardcoded API key allows admin token forgeryEyesOfNetwork 5.3 ships with a hardcoded API key (EONAPI_KEY in include/api_functions.php for API version 2.4.2) that is identical across all install…KEVEPSS 92%analysed7.8CVE-2020-8655EyesOfNetwork sudoers misconfiguration allows apache-to-root privilege escalationEyesOfNetwork 5.3 ships a sudoers configuration that lets the apache user run arbitrary commands as root through a crafted NSE script for nmap 7. Bec…KEVEPSS 60%analysed9.8CVE-2022-41572Eyesofnetwork incorrect default permissions vulnerabilityAn issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root…EPSS 0.59%9.8CVE-2022-41570Eyesofnetwork sql injection vulnerabilityAn issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.EPSS 0.79%9.8CVE-2022-41571Eyesofnetwork vulnerabilityAn issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.EPSS 1.1%9.8CVE-2021-40643Eyesofnetwork vulnerabilityEyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" a…EPSS 2.9%9.8CVE-2021-27514Eyesofnetwork improper restriction of authentication attempts vulnerabilityEyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (s…EPSS 3.5%9.8CVE-2020-27886Eyesofnetwork sql injection vulnerabilityAn issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticate…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2020-8654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.