CVE-2020-36885
Severity CVSS v4.0:
CRITICAL
Type:
CWE-787
Out-of-bounds Write
Publication date:
10/12/2025
Last modified:
10/12/2025
Description
Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can exploit the vulnerability by sending a crafted POST request with oversized data to the FTP client functionality, potentially causing remote code execution or denial of service.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://pro.sony/en_NL/support-resources/snc-dh120/
- https://pro.sony/en_NL/support-resources/snc-dh120/software/mpengb00000928
- https://www.exploit-db.com/exploits/48842
- https://www.vulncheck.com/advisories/sony-ipela-network-camera-remote-stack-buffer-overflow-via-ftpclientcgi
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5596.php



