CVE-2021-33963

CRITICAL

China Mobile An Lianbao WF-1 v1.0.1 - OS Command Injection via macType Parameter

Title source: llm
STIX 2.1

Description

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

Scores

CVSS v3 9.8
EPSS 0.0307
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
chinamobile/an_lianbao_wf-1_firmware 1.0.1
Published Jan 15, 2022
Tracked Since Feb 18, 2026