CVE-2021-21805
advantech r-seenet Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-21805 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
r-seenetBrowse advantech / r-seenet | VulnCheck | Version data not supplied | |
Advantech | CVE List | Advantech R-SeeNet 2.4.12 (20.10.2020) | affected |
Nuclei templates
1ProjectDiscoveryCRITICALAdvantech R-SeeNet 2.4.12 - OS Command InjectionCVSS 9.8
Advantech R-SeeNet 2.4.12 is susceptible to remote OS command execution via the ping.php script functionality. An attacker, via a specially crafted HTTP request, can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.
Remediation
Update to the latest version of Advantech R-SeeNet to mitigate this vulnerability.
Source: ProjectDiscovery