PT-2021-3074 · Cisco · Cisco Small Business 500 Series Wireless Access Points+2
Published
2021-05-19
·
Updated
2021-05-26
·
CVE-2021-1549
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business 100, 300, 500 Series Wireless Access Points (affected versions not specified)
Description
The issue is related to insufficient validation of arguments passed to a command in the web-based management interface of certain Cisco Small Business Wireless Access Points. This could allow a remote attacker to perform command injection attacks against an affected device. The attacker must have valid administrative credentials for the device to exploit this issue. The exploitation involves sending crafted HTTP requests to the web-based management interface, potentially allowing the attacker to execute arbitrary commands with root privileges on the device.
Recommendations
For Cisco Small Business 100, 300, 500 Series Wireless Access Points, consider disabling remote access to the web-based management interface until a patch is available.
Restrict access to the web-based management interface to minimize the risk of exploitation.
Avoid using the web-based management interface for administrative tasks until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Small Business 100 Series Wireless Access Points
Cisco Small Business 300 Series Wireless Access Points
Cisco Small Business 500 Series Wireless Access Points