PT-2021-21317 · Prolink · Prolink Prc2402M

Ayrx

·

Published

2021-08-06

·

Updated

2021-08-12

·

CVE-2021-36706

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProLink PRC2402M versions 1.0.18 and older
Description The issue concerns a command injection in the set sys cmd function within the adm.cgi binary. This function is accessible when the page parameter is set to sysCMD, allowing the command parameter's value to be passed directly to the system.
Recommendations For ProLink PRC2402M versions 1.0.18 and older, as a temporary workaround, consider restricting access to the adm.cgi binary or disabling the set sys cmd function until a patch is available. Avoid using the command parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36706

Affected Products

Prolink Prc2402M