Record summary

CVE-2021-23241 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMMERCUSYS Mercury X18G 1.0.5 Router - Local File InclusionCVSS 5.3

MERCUSYS Mercury X18G 1.0.5 devices are vulnerable to local file inclusion via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.

Impact

An attacker can exploit this vulnerability to access sensitive information, such as configuration files, credentials, or other sensitive data stored on the router.

Remediation

Apply the latest firmware update provided by the vendor to fix the LFI vulnerability and ensure proper input validation is implemented.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2021cveiotlfiroutermercusysvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:o:mercusys:mercury_x18g_firmware:1.0.5:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4