CVE-2021-21875: OS Command Injection
Published Dec 22, 2021
·Updated
A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
2 affected components
Lantronix Premierwave 2050 Firmware=8.9.0.0-r4
Lantronix PremierWave 2050
Event History
Dec 22, 2021
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-21875 vulnerability about?
The vulnerability CVE-2021-21875 allows arbitrary command execution through a specially-crafted HTTP request in the EC keypasswd parameter.
2
How severe is the CVE-2021-21875 vulnerability?
CVE-2021-21875 has a severity rating of 9.1 (Critical).
3
Which software is affected by CVE-2021-21875?
Lantronix Premierwave 2050 Firmware version 8.9.0.0-r4 is affected by CVE-2021-21875.
4
Can an authenticated HTTP request trigger CVE-2021-21875?
Yes, an attacker can use an authenticated HTTP request to trigger the CVE-2021-21875 vulnerability.