CVE-2021-1401

HIGH

Cisco Small Business WAP125, WAP131, WAP150, WAP351, WAP361, WAP581 Firmware - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to obtain sensitive information from or inject arbitrary commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN71263107/index.html

Scores

CVSS v3 8.8
EPSS 0.0098
EPSS Percentile 77.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-269
Status published
Products (6)
cisco/wap125_firmware < 1.0.3.1
cisco/wap131_firmware < 1.0.2.17
cisco/wap150_firmware < 1.1.2.4
cisco/wap351_firmware < 1.0.2.17
cisco/wap361_firmware < 1.1.2.4
cisco/wap581_firmware < 1.0.3.1
Published May 06, 2021
Tracked Since Feb 18, 2026