PT-2022-10305 · China Mobile · China Mobile An Lianbao Wf-1
Published
2022-01-18
·
Updated
2022-01-24
·
CVE-2021-33964
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
China Mobile An Lianbao WF-1 router version 1.0.1
Description
The issue concerns a command injection vulnerability in the web interface of the China Mobile An Lianbao WF-1 router. Specifically, the API endpoint "/api/ZRRuleFilter/set firewall level" is vulnerable when it receives parameters via a POST request. The
firewall level parameter is susceptible to command injection, allowing an attacker to execute remote commands.Recommendations
For China Mobile An Lianbao WF-1 router version 1.0.1, as a temporary workaround, consider disabling the
/api/ZRRuleFilter/set firewall level API endpoint until a patch is available. Avoid using the firewall level parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
China Mobile An Lianbao Wf-1