Security Advisory

CVE-2020-36907

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-06 15:52:21
Last updated 2026-03-23 15:43:28
Assigner VulnCheck
State PUBLISHED

Description

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.