CVE detail
CVE-2020-25195 — CVE-2020-25195
Published 2020-12-15 · Modified 2026-06-17 · Vendor hosteng · Product h0-ecom100_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0145
EPSS probability
exploitation probability, 30d
71.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References