CVE-2021-42165

HIGH

MitraStar GPT-2541GNAC-N1 Firmware - Authenticated OS Command Injection via DeviceInfo Path Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-42165. PoCs published by Leonardo Nicolas Servalli.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in the Mitrastar GPT-2541GNAC-N1 router's restricted shell. By appending '&&/bin/bash' to the 'deviceinfo show file' command, an attacker can spawn a root shell due to improper handling of special characters.

Description

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

Exploits (1)

exploitdb WORKING POC
by Leonardo Nicolas Servalli · textremotehardware
https://www.exploit-db.com/exploits/50351

This exploit leverages a command injection vulnerability in the Mitrastar GPT-2541GNAC-N1 router's restricted shell. By appending '&&/bin/bash' to the 'deviceinfo show file' command, an attacker can spawn a root shell due to improper handling of special characters.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Mitrastar GPT-2541GNAC-N1 (Firmware BR_g3.5_100VNZ0b33)
Auth required
Prerequisites: SSH access to the router · Valid credentials (default or user-provided)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50351

Scores

CVSS v3 8.8
EPSS 0.1310
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
mitrastar/gpt-2541gnac-n1_firmware br_g3.5_100vnz0b33
Published May 03, 2022
Tracked Since Feb 18, 2026