CVE-2020-37123Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-05: 2Mentions · 2026-02-11: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-11: 102-0502-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-052
Disclosure2
2026-02-111
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2020-37123 - critical 🚨 Pinger 1.0 - Remote Code Execution > Pinger 1.0 contains a remote code execution vulnerability that allows attackers to in... 👾 https://cloud.projectdiscovery.io/library/CVE-2020-37123 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2020‑37123 as a critical remote code execution flaw in Pinger 1.0, providing minimal technical detail and no evidence of exploitation or patching.

    01031145
    890 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2020-37123 Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit… https://www.cve.org/CVERecord?id=CVE-2020-37123

    Post summary

    The post announces CVE‑2020‑37123, a remote code execution flaw in Pinger 1.0 that permits shell command injection via ping and socket parameters, without detailing exploits, patches, or active use.

    01020148
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2020-37123: Pinger 1.0 - Remote Code Executi... Trivial RCE in Pinger 1.0 via unsanitized ping.php parameters enables full command injection - write arbitrary PHP and ... https://zerodaysignal.com/vulnerability/CVE-2020-37123 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2020-37123, noting a trivial remote code execution flaw in Pinger 1.0 that allows full command injection via unsanitized ping.php parameters. No PoC, exploit code, patch, or active exploitation is referenced.

    0101065
    132 followersView on X

Explore more