CVE-2021-20991: Fibaro Home Center Authenticated remote command execution
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fibaro Home Center 2 and Lite devices vulnerability?
The vulnerability ID for this Fibaro Home Center 2 and Lite devices vulnerability is CVE-2021-20991.
What is the severity of CVE-2021-20991?
The severity of CVE-2021-20991 is critical with a CVSS score of 8.8.
What is the affected software of CVE-2021-20991?
The affected software of CVE-2021-20991 includes Fibaro Home Center 2 devices with firmware version 4.540 and older, as well as Fibaro Home Center Lite devices with firmware version 4.540 and older.
How can an authenticated user exploit CVE-2021-20991?
An authenticated user can exploit CVE-2021-20991 by running commands as the root user using a command injection vulnerability.
Are Fibaro Home Center 2 and Lite devices vulnerable to CVE-2021-20991?
Yes, Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older are vulnerable to CVE-2021-20991.