PT-2022-10305 · China Mobile · China Mobile An Lianbao Wf-1

Published

2022-01-18

·

Updated

2022-01-24

·

CVE-2021-33964

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions China Mobile An Lianbao WF-1 router version 1.0.1
Description The issue concerns a command injection vulnerability in the web interface of the China Mobile An Lianbao WF-1 router. Specifically, the API endpoint "/api/ZRRuleFilter/set firewall level" is vulnerable when it receives parameters via a POST request. The firewall level parameter is susceptible to command injection, allowing an attacker to execute remote commands.
Recommendations For China Mobile An Lianbao WF-1 router version 1.0.1, as a temporary workaround, consider disabling the /api/ZRRuleFilter/set firewall level API endpoint until a patch is available. Avoid using the firewall level parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33964

Affected Products

China Mobile An Lianbao Wf-1