sercomm.com
http://sercomm.com/ CVE-2021-27132
CRITICALNuclei
Sercomm VD625 Smart Modems - CRLF Injection
Record summary
CVE-2021-27132 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALSercomm VD625 Smart Modems - CRLF InjectionCVSS 9.8
Sercomm AGCOMBO VD625 Smart Modems with firmware version AGSOT_2.1.0 are vulnerable to Carriage Return Line Feed (CRLF) injection via the Content-Disposition header.
Impact
Successful exploitation of this vulnerability could lead to various attacks, including session hijacking, cross-site scripting (XSS), and cache poisoning.
Remediation
Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-74
Authorsgeeknik
Template tagscve2021cvecrlfinjectionsercommxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:sercomm:agcombo_vd625_firmware:agsot_2.1.0:*:*:*:*:*:*:*
https://cybertuz.com/blog/post/crlf-injection-CVE-2021-27132 http://sercomm.com/ https://nvd.nist.gov/vuln/detail/CVE-2021-27132 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3cybertuz.com
https://cybertuz.com/blog/post/crlf-injection-CVE-2021-27132 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-27132