nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-21872 CVE-2021-21872
CRITICAL
lantronix premierwave_2050_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-21872 has a selected CVSS score of 9.9 (critical).
Description
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 7, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
premierwave_2050_firmwareBrowse lantronix / premierwave_2050_firmware | VulnCheck | Version data not supplied | |
Lantronix | CVE List | Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU) | affected |
References
2talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1312