First published: Fri Jul 16 2021(Updated: )
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech R-SeeNet | =2.4.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21804 is a local file inclusion (LFI) vulnerability in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
CVE-2021-21804 is considered critical with a severity score of 9.8 out of 10.
CVE-2021-21804 allows arbitrary PHP code execution in Advantech R-SeeNet v 2.4.12 (20.10.2020) when a specially crafted HTTP request is sent.
An attacker can exploit CVE-2021-21804 by sending a crafted HTTP request to trigger the local file inclusion vulnerability and execute arbitrary PHP code.
At the time of this report, no official fix or patch has been released for CVE-2021-21804. It is recommended to update to a newer version or apply any available security updates provided by the vendor.