CVE-2021-21881
lantronix premierwave_2050_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-21881 has a selected CVSS score of 9.9 (critical); EIP currently links 1 Nuclei template.
Description
An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 19, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
premierwave_2050_firmwareBrowse lantronix / premierwave_2050_firmware | VulnCheck | Version data not supplied | |
Lantronix | CVE List | Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU) | affected |
Nuclei templates
1ProjectDiscoveryCRITICALLantronix PremierWave 2050 8.9.0.0R4 - Remote Command InjectionCVSS 9.9
Lantronix PremierWave 2050 8.9.0.0R4 contains an OS command injection vulnerability. A specially-crafted HTTP request can lead to command in the Web Manager Wireless Network Scanner. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, or complete compromise of the affected device.
Remediation
Apply the latest firmware update provided by Lantronix to mitigate the vulnerability.
Source: ProjectDiscovery