PT-2026-21285 · Prolink · Prolink Prc2402M
Published
2026-02-20
·
Updated
2026-04-11
·
CVE-2021-35402
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PROLiNK PRC2402M versions prior to 2021-06-13
Description
The PROLiNK PRC2402M router firmware contains a flaw that allows for arbitrary OS command execution. The issue resides in the
live api.cgi script when handling the page=satellite list request. Specifically, the ip parameter within the satellite status function is susceptible to shell metacharacter injection. An attacker can leverage this to execute commands on the device.Recommendations
Update PROLiNK PRC2402M firmware to version 2021-06-13 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prolink Prc2402M