{"id":"CVE-2020-15362","details":"wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.","aliases":["GHSA-m6rw-m2v9-7hx4"],"modified":"2026-07-09T02:49:38.572899Z","published":"2020-06-29T17:15:11.430Z","references":[{"type":"EVIDENCE","url":"https://github.com/thingsSDK/wifiscanner/issues/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thingssdk/wifiscanner","events":[{"introduced":"9695ed53fba4e1b7a56a918c009cba07ead8a5a4"},{"last_affected":"9695ed53fba4e1b7a56a918c009cba07ead8a5a4"}],"database_specific":{"cpe":"cpe:2.3:a:thingssdk:wifiscanner:1.0.1:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"1.0.1"},{"last_affected":"1.0.1"}],"source":"CPE_STRING"}}],"versions":["1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15362.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}