Vulnerability record · CVE-2020-8654 · published 7 February 2020
CVE-2020-8654: EyesOfNetwork AutoDiscovery module OS command injection
EEyesofnetwork · Eyesofnetwork
EyesOfNetwork 5.3 lets an authenticated web user with sufficient privileges abuse the AutoDiscovery module to run arbitrary OS commands through the autodiscovery.php target field. Because the flaw is command injection reachable over the network, it gives a privileged user a path to full server compromise.
Description
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote command execution with high impact and has public exploit code plus a very high EPSS score, though it requires valid privileged credentials.
What it is
EyesOfNetwork 5.3 lets an authenticated web user with sufficient privileges abuse the AutoDiscovery module to run arbitrary OS commands through the autodiscovery.php target field. Because the flaw is command injection reachable over the network, it gives a privileged user a path to full server compromise.
Impact
An attacker with a valid privileged account can execute arbitrary operating system commands on the EyesOfNetwork host, leading to full control of the application server and any data or credentials it holds.
Attack surface
Reached over the network via the /module/module_frame/index.php autodiscovery.php target field. Authentication is required, and the description indicates the user needs sufficient privileges; no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.9118, 99.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Apply the vendor fix for the AutoDiscovery command injection in EyesOfNetwork 5.3 or upgrade to a patched release.
- Restrict access to the AutoDiscovery module and /module/module_frame/index.php to only trusted administrators.
- Review and minimize accounts with privileges that allow use of AutoDiscovery.
- Validate or sanitize the autodiscovery.php target field so it cannot contain shell metacharacters.
- Monitor and alert on unexpected OS command execution from the web application process.
Detection
- Inspect web logs for requests to /module/module_frame/index.php with autodiscovery.php and suspicious target parameter values containing shell metacharacters.
- Monitor for child processes spawned by the web server or PHP process that are unusual for normal application behavior.
- Alert on outbound connections or command activity originating from the EyesOfNetwork host shortly after AutoDiscovery requests.
- Audit AutoDiscovery module usage and flag changes or runs by accounts that do not normally use it.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/EyesOfNetworkCommunity/eonweb/issues/50 | ExploitIssue TrackingThird Party Advisory |
| http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/EyesOfNetworkCommunity/eonweb/issues/50 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2020-8654 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8654), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.