CVE-2021-45232

CRITICAL NUCLEI

Apache APISIX Dashboard < 2.10.1 - Unauthenticated API Access via Gin Framework Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 9 public exploits for CVE-2021-45232. PoCs published by wuppp, YutuSec, fany0r. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2021-45232, an RCE vulnerability in Apache APISIX Dashboard. It leverages the migrate/import endpoint to inject a malicious route configuration that executes arbitrary commands via Lua script.

Description

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

Exploits (9)

nomisec WORKING POC 78 stars
by wuppp · poc
https://github.com/wuppp/cve-2021-45232-exp

This PoC exploits CVE-2021-45232, an RCE vulnerability in Apache APISIX Dashboard. It leverages the migrate/import endpoint to inject a malicious route configuration that executes arbitrary commands via Lua script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Network access to the APISIX Dashboard admin interface · Import/export functionality enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 7 stars
by YutuSec · poc
https://github.com/YutuSec/Apisix_Crack

This repository contains a Go-based exploit for CVE-2021-45232, an unauthenticated API access vulnerability in Apache APISIX. The PoC checks for unauthenticated access to the admin API and demonstrates command execution via route manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache APISIX (versions affected by CVE-2021-45232)
No auth needed
Prerequisites: Network access to the APISIX admin interface · Admin API endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by fany0r · poc
https://github.com/fany0r/CVE-2021-45232-RCE

This PoC exploits CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard, to achieve remote code execution (RCE) by importing a malicious route configuration that executes arbitrary commands via Lua script injection.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Target APISIX Dashboard exposed and vulnerable · Network access to the management port (default: 9000)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 1 stars
by Ilovewomen · poc
https://github.com/Ilovewomen/cve-2021-45232

This repository provides a description and proof-of-concept for CVE-2021-45232, an authentication bypass vulnerability in Apache APISIX Dashboard. The vulnerability allows unauthorized access to the `/apisix/admin/migrate/export` endpoint due to inconsistent framework usage (gin vs. droplet).

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Network access to the target Apache APISIX Dashboard instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 1 stars
by LTiDi2000 · poc
https://github.com/LTiDi2000/CVE-2021-45232

This repository provides a writeup and basic PoC for CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard. It includes FOFA queries, affected versions, and mitigation steps but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Network access to the target Apache APISIX Dashboard instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by dskho · poc
https://github.com/dskho/CVE-2021-45232

This repository contains a Python script to scan for CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard, and also checks for default credentials. It performs HTTP requests to specific endpoints to detect the vulnerability and logs results.

Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache APISIX Dashboard
No auth needed
Prerequisites: Network access to the target Apache APISIX Dashboard
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by badboycxcc · poc
https://github.com/badboycxcc/CVE-2021-45232-POC

This repository contains a README with images and links related to CVE-2021-45232 but lacks actual exploit code or technical details. It appears to be a placeholder or informational writeup.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by jxpsx · poc
https://github.com/jxpsx/CVE-2021-45232-RCE

This repository provides a proof-of-concept for CVE-2021-45232, an unauthenticated RCE vulnerability in Apache APISIX Dashboard versions prior to 2.10.1. The exploit leverages an unauthenticated API endpoint to achieve remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Access to the target Apache APISIX Dashboard instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by Osyanina · poc
https://github.com/Osyanina/westone-CVE-2021-45232-scanner

This repository provides a scanner for CVE-2021-45232, an authentication bypass vulnerability in Apache APISIX Dashboard versions prior to 2.10.1. The vulnerability arises from inconsistent framework usage, allowing unauthorized access to certain APIs.

Classification
Scanner 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache APISIX Dashboard < 2.10.1
No auth needed
Prerequisites: Network access to the target Apache APISIX Dashboard
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Apache APISIX Dashboard <2.10.1 - API Unauthorized Access
CRITICALby Mr-xn

References (2)

Core 2
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/979qbl6vlm8269fopfyygnxofgqyn6k5
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/12/27/1

Scores

CVSS v3 9.8
EPSS 0.8583
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
apache/apisix_dashboard < 2.10.1
Published Dec 27, 2021
Tracked Since Feb 18, 2026