CVE-2020-28580
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 45%
exploitation probability
45%top 1% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.
Affected products
Trend Micro · Trend Micro InterScan Web Security Virtual Appliance