PT-2022-10891 · Korenix · Korenix Jetwave 2212G+3
Published
2022-02-06
·
Updated
2022-02-11
·
CVE-2021-39280
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Korenix JetWave 2212X versions 1.9.0 and earlier
Korenix JetWave 2212S versions 1.9.0 and earlier
Korenix JetWave 2212G versions 1.7 and earlier
Korenix JetWave 3220 V3 versions 1.5.0 and earlier
Korenix JetWave 3420 V3 versions 1.5.0 and earlier
Korenix JetWave 2311 versions prior to 2022-01-31
Description
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via the "/syscmd.asp" API endpoint. This issue can be exploited by authenticated users.
Recommendations
For Korenix JetWave 2212X versions 1.9.0 and earlier, update to version 1.9.1 or later.
For Korenix JetWave 2212S versions 1.9.0 and earlier, update to version 1.9.1 or later.
For Korenix JetWave 2212G versions 1.7 and earlier, update to version 1.8 or later.
For Korenix JetWave 3220 V3 versions 1.5.0 and earlier, update to version 1.5.1 or later.
For Korenix JetWave 3420 V3 versions 1.5.0 and earlier, update to version 1.5.1 or later.
For Korenix JetWave 2311 versions prior to 2022-01-31, ensure that the device is updated to a version released after 2022-01-31.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Korenix Jetwave 2212G
Korenix Jetwave 2311
Korenix Jetwave 3220 V3
Korenix Jetwave 3420 V3