fiberhome.com
http://fiberhome.com/ CVE-2021-42912
HIGH
fiberhome an5506-01-a_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-42912 has a selected CVSS score of 8.8 (high).
Description
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 20, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
an5506-01-a_firmwareBrowse fiberhome / an5506-01-a_firmware | VulnCheck | Version data not supplied | |
References
5onu.com
http://onu.com/ medium.com
https://medium.com/%40windsormoreira/fiberhome-an5506-os-command-injection-cve-2021-42912-10b64fd10ce2 medium.com
https://medium.com/@windsormoreira/fiberhome-an5506-os-command-injection-cve-2021-42912-10b64fd10ce2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-42912