Record summary

CVE-2021-27132 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALSercomm VD625 Smart Modems - CRLF InjectionCVSS 9.8

Sercomm AGCOMBO VD625 Smart Modems with firmware version AGSOT_2.1.0 are vulnerable to Carriage Return Line Feed (CRLF) injection via the Content-Disposition header.

Impact

Successful exploitation of this vulnerability could lead to various attacks, including session hijacking, cross-site scripting (XSS), and cache poisoning.

Remediation

Apply the latest firmware update provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-74
Authorsgeeknik
Template tagscve2021cvecrlfinjectionsercommxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:sercomm:agcombo_vd625_firmware:agsot_2.1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3