Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Extremenetworks
Extremenetworks aerohive Hiveos |
|
| Vendors & Products |
Extremenetworks
Extremenetworks aerohive Hiveos |
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption. | |
| Title | Extreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service | |
| Weaknesses | CWE-770 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-23T15:43:28.183Z
Reserved: 2026-01-03T14:10:13.300Z
Link: CVE-2020-36907
Updated: 2026-01-06T19:05:50.764Z
Status : Deferred
Published: 2026-01-06T16:15:46.327
Modified: 2026-04-15T00:35:42.020
Link: CVE-2020-36907
No data.
OpenCVE Enrichment
Updated: 2026-01-07T10:09:04Z