CVE-2021-33964

HIGH

China Mobile An Lianbao WF-1 Firmware V1.0.1 - OS Command Injection via firewall_level Parameter

Title source: llm
STIX 2.1

Description

China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

Scores

CVSS v3 8.8
EPSS 0.0287
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
chinamobile/an_lianbao_wf-1_firmware 1.0.1
Published Jan 18, 2022
Tracked Since Feb 18, 2026