PT-2021-18677 · China Mobile · China Mobile An Lianbao Wf-1

Published

2021-04-29

·

Updated

2022-05-03

·

CVE-2021-30230

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions China Mobile An Lianbao WF-1 router version 1.0.1
Description The issue concerns the "api/ZRFirmware/set time zone" interface, which allows remote attackers to execute arbitrary commands. This is achieved by injecting shell metacharacters into the zonename parameter.
Recommendations For China Mobile An Lianbao WF-1 router version 1.0.1, avoid using the zonename parameter in the "api/ZRFirmware/set time zone" interface until the issue is resolved. As a temporary workaround, consider restricting access to this interface to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-30230

Affected Products

China Mobile An Lianbao Wf-1