CVE-2020-16152 is a remote code execution vulnerability in the NetConfig UI administrative interface of Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through version 10.0r8a. The vulnerability allows an attacker to inject PHP code into a log file via remote HTTP requests and subsequently execute this code as the root user by traversing to the log file through the web interface.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module targeting Aerohive NetConfig (now Extreme Networks) web interface, specifically versions 10.0r8a build-242466 and older. The exploit leverages a Local File Inclusion (LFI) vulnerability (CVE-2020-16152) combined with log poisoning to achieve unauthenticated remote code execution as root. The module is weaponized, supporting both meterpreter and reverse shell payloads, and can automatically clean up log evidence (though this is risky and disabled by default). The exploit works by poisoning the /tmp/messages log file with PHP code, then triggering LFI via crafted HTTP requests to execute arbitrary commands. The main endpoints involved are /index.php5 (for version detection) and /action.php5 (for exploitation). The code is written in Ruby and is structured as a standard Metasploit exploit module, making it easy to use within the Metasploit framework. The exploit is highly effective, but may cause the target web application to hang while a shell is open. The module provides options for automatic cleanup and supports both ARM and generic Unix command payloads.
This repository provides a working exploit for CVE-2020-16152, a critical vulnerability in Aerohive/Extreme Networks HiveOS (IQ Engine) administrative web interface. The exploit leverages a combination of log poisoning and a local file inclusion (LFI) vulnerability due to PHP string truncation, allowing an attacker to achieve remote code execution as root on affected devices. The main exploit script, 'CVE-2020-16152.py', is a Python script that first injects a PHP webshell into the '/tmp/messages' log file by submitting a crafted username to the login endpoint. It then triggers the LFI by sending a specially crafted POST request to the 'action.php5' endpoint, causing the server to include and execute the poisoned log file. The exploit requires the web interface to be enabled and accessible. The repository also includes a detailed README.md explaining the vulnerability, affected products, and a proof-of-concept usage example. No framework is used; the exploit is standalone and operational, providing a clear path to remote root access on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.