Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware Rev.15.02.09 and earlier, RTX1200 firmware Rev.10.01.76 and earlier, RTX1210 firmware Rev.14.01.33 and earlier, RTX3500 firmware Rev.14.00.26 and earlier, and RTX5000 firmware Rev.14.00.26 and earlier), Yamaha Broadband VoIP Router(NVR500 firmware Rev.11.00.38 and earlier), and Yamaha Firewall(FWX120 firmware Rev.11.03.27 and earlier) allow remote attackers to cause a denial of service via unspecified vectors.
Conclusion & alert: CVE-2020-5548 is rated Moderate Risk (58.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.86% | 1.32% | +0.47% |
| 2 | 2025-11-18 | 1.32% | 0.86% | -0.47% |
| 3 | 2025-06-21 | — | 1.32% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| yamaha | rtx830_firmware | <= 15.02.09 | cpe:2.3:o:yamaha:rtx830_firmware:*:*:*:*:*:*:*:* |
| yamaha | nvr510_firmware | <= 15.01.14 | cpe:2.3:o:yamaha:nvr510_firmware:*:*:*:*:*:*:*:* |
| yamaha | nvr700w_firmware | <= 15.00.15 | cpe:2.3:o:yamaha:nvr700w_firmware:*:*:*:*:*:*:*:* |
| yamaha | rtx1210_firmware | <= 14.01.33 | cpe:2.3:o:yamaha:rtx1210_firmware:*:*:*:*:*:*:*:* |
| yamaha | rtx5000_firmware | <= 14.00.26 | cpe:2.3:o:yamaha:rtx5000_firmware:*:*:*:*:*:*:*:* |
| yamaha | rtx3500_firmware | <= 14.00.26 | cpe:2.3:o:yamaha:rtx3500_firmware:*:*:*:*:*:*:*:* |
| yamaha | fwx120_firmware | <= 11.03.27 | cpe:2.3:o:yamaha:fwx120_firmware:*:*:*:*:*:*:*:* |
| yamaha | rtx810_firmware | <= 11.01.33 | cpe:2.3:o:yamaha:rtx810_firmware:*:*:*:*:*:*:*:* |
| yamaha | nvr500_firmware | <= 11.00.38 | cpe:2.3:o:yamaha:nvr500_firmware:*:*:*:*:*:*:*:* |
| yamaha | rtx1200_firmware | <= 10.01.76 | cpe:2.3:o:yamaha:rtx1200_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN38732359.html | Mitigation Vendor Advisory |
| https://jvn.jp/en/jp/JVN38732359/index.html | Third Party Advisory |