Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-7240 Details

Description

Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Configuration). Note: According to the description, the vulnerability requires a fully authenticated super-user account using a webUI function that allows super users to edit a script supposed to execute OS commands. The given weakness enumeration (CWE-78) is not applicable in this case as it refers to abusing functions/input fields not supposed to be accepting OS commands by using 'Special Elements.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')[email protected]

Affected Products

ProductVersions
meinbergglobal lantime m300 firmware
All versions

CPE

  • cpe:2.3:o:meinbergglobal:lantime_m300_firmware:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
meinbergglobal lantime m300
All versions

CPE

  • cpe:2.3:h:meinbergglobal:lantime_m300:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
meinbergglobal lantime m1000 firmware
All versions

CPE

  • cpe:2.3:o:meinbergglobal:lantime_m1000_firmware:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
meinbergglobal lantime m1000
All versions

CPE

  • cpe:2.3:h:meinbergglobal:lantime_m1000:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-7240
NVD Published Date:
Jan 20, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-7240 Details - Not Deferred