CVE-2021-33538

HIGH

Weidmueller Industrial WLAN - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
https://cert.vde.com/en-us/advisories/vde-2021-026

Scores

CVSS v3 8.8
EPSS 0.0105
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (8)
weidmueller/ie-wl-bl-ap-cl-eu_firmware < 1.16.18
weidmueller/ie-wl-bl-ap-cl-us_firmware < 1.16.18
weidmueller/ie-wl-vl-ap-br-cl-eu_firmware < 1.16.18
weidmueller/ie-wl-vl-ap-br-cl-us_firmware < 1.16.18
weidmueller/ie-wlt-bl-ap-cl-eu_firmware < 1.16.18
weidmueller/ie-wlt-bl-ap-cl-us_firmware < 1.16.18
weidmueller/ie-wlt-vl-ap-br-cl-eu_firmware < 1.16.18
weidmueller/ie-wlt-vl-ap-br-cl-us_firmware < 1.16.18
Published Jun 25, 2021
Tracked Since Feb 18, 2026