CVE-2021-40870

CRITICAL KEV NUCLEI

Aviatrix Controller <6.5-1804.1922 - Code Injection

Title source: llm

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Exploits (6)

nomisec WORKING POC 15 stars
by 0xAgun · remote
https://github.com/0xAgun/CVE-2021-40870
nomisec WORKING POC 3 stars
by orangmuda · remote
https://github.com/orangmuda/CVE-2021-40870
nomisec WORKING POC 2 stars
by JoyGhoshs · remote
https://github.com/JoyGhoshs/CVE-2021-40870
nomisec WORKING POC
by System00-Security · remote
https://github.com/System00-Security/CVE-2021-40870
inthewild WORKING POC
poc
https://github.com/thomsdev/cve-2021-40870
inthewild WORKING POC
poc
https://github.com/byteofjoshua/cve-2021-40870

Nuclei Templates (1)

Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution
CRITICALby pikpikcu
Shodan: http.title:"aviatrix cloud controller"
FOFA: title="aviatrix cloud controller"

Scores

CVSS v3 9.8
EPSS 0.9426
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-01-18
VulnCheck KEV 2021-12-21
InTheWild.io 2021-12-21
ENISA EUVD EUVD-2021-28025
CWE
CWE-23
Status published
Products (1)
aviatrix/controller 6.2 - 6.2.2043
Published Sep 13, 2021
KEV Added Jan 18, 2022
Tracked Since Feb 18, 2026