PT-2021-14807 · Lantronix · Lantronix Premierwave 2050

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-09-30

·

CVE-2021-21872

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lantronix PremierWave 2050 version 8.9.0.0R4
Description A command injection issue exists in the Web Manager Diagnostics: Traceroute functionality, allowing arbitrary command execution via a specially-crafted HTTP request. An attacker can trigger this issue by making an authenticated HTTP request.
Recommendations For version 8.9.0.0R4, consider restricting access to the Web Manager Diagnostics: Traceroute functionality until a fix is available. As a temporary workaround, limit the ability to make authenticated HTTP requests to the vulnerable functionality to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21872

Affected Products

Lantronix Premierwave 2050