CVE-2021-21872: OS Command Injection
Published Dec 22, 2021
·Updated
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
2 affected components
Lantronix Premierwave 2050 Firmware=8.9.0.0-r4
Lantronix PremierWave 2050
Event History
Dec 22, 2021
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21872?
The severity of CVE-2021-21872 is critical with a CVSS score of 9.9.
2
How does the OS command injection vulnerability CVE-2021-21872 occur?
The OS command injection vulnerability CVE-2021-21872 occurs in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4 due to a specially-crafted HTTP request.
3
What can an attacker achieve with CVE-2021-21872?
An attacker can achieve arbitrary command execution by making an authenticated HTTP request to trigger the vulnerability CVE-2021-21872.