CVE-2021-20844: Medium severity ntt-west biz box rtx830 firmware vulnerability
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20844.
What is the severity of CVE-2021-20844?
The severity of CVE-2021-20844 is medium with a CVSS score of 5.7.
Which software versions are affected by CVE-2021-20844?
RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier are affected by CVE-2021-20844.
How can a remote attacker exploit CVE-2021-20844?
A remote authenticated attacker can exploit CVE-2021-20844 by obtaining sensitive information through improper neutralization of HTTP request headers for scripting syntax in the Web GUI.
Where can I find more information about CVE-2021-20844?
More information about CVE-2021-20844 can be found at the following references: [http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU91161784.html](http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU91161784.html), [https://business.ntt-east.co.jp/topics/2021/11_09.html](https://business.ntt-east.co.jp/topics/2021/11_09.html), [https://jvn.jp/en/vu/JVNVU91161784/index.html](https://jvn.jp/en/vu/JVNVU91161784/index.html).