CVE-2021-42165

HIGH

Mitrastar Gpt-2541gnac-n1 Firmware - OS Command Injection

Title source: rule

Description

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

Exploits (1)

exploitdb WORKING POC
by Leonardo Nicolas Servalli · textremotehardware
https://www.exploit-db.com/exploits/50351

Scores

CVSS v3 8.8
EPSS 0.3955
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
mitrastar/gpt-2541gnac-n1_firmware br_g3.5_100vnz0b33
Published May 03, 2022
Tracked Since Feb 18, 2026