First published: Thu Apr 15 2021(Updated: )
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fibaro Home Center 2 Firmware | <=4.540 | |
Fibaro Home Center 2 | ||
Fibaro Home Center Lite Firmware | <=4.540 | |
Fibaro Home Center Lite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Fibaro Home Center 2 and Lite devices vulnerability is CVE-2021-20991.
The severity of CVE-2021-20991 is critical with a CVSS score of 8.8.
The affected software of CVE-2021-20991 includes Fibaro Home Center 2 devices with firmware version 4.540 and older, as well as Fibaro Home Center Lite devices with firmware version 4.540 and older.
An authenticated user can exploit CVE-2021-20991 by running commands as the root user using a command injection vulnerability.
Yes, Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older are vulnerable to CVE-2021-20991.