PT-2021-14809 · Lantronix · Premierwave 2050 Firmware

Matt Wiseman

·

Published

2021-12-22

·

Updated

2022-10-05

·

CVE-2021-21877

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned.
Description The issue allows specially-crafted HTTP requests to lead to arbitrary command execution in "GET" requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21877

Affected Products

Premierwave 2050 Firmware