Record summary

CVE-2021-21872 has a selected CVSS score of 9.9 (critical).

Description

An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 7, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Lantronix

CVE ListLantronix PremierWave 2050 8.9.0.0R4 (in QEMU)affected

References

2