CVE-2026-3820

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
04/06/2026
Last modified:
22/07/2026

Description

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. <br /> An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation.<br /> <br /> Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.

References to Advisories, Solutions, and Tools