CVE-2021-21878: Medium severity lantronix premierwave 2050 firmware vulnerability
A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21878?
CVE-2021-21878 is considered a high severity vulnerability due to the potential for local file inclusion attacks.
How do I fix CVE-2021-21878?
To fix CVE-2021-21878, upgrade to a patched version of the Lantronix PremierWave 2050 firmware.
What versions of firmware are affected by CVE-2021-21878?
CVE-2021-21878 affects the Lantronix PremierWave 2050 firmware version 8.9.0.0-R4.
Can CVE-2021-21878 be exploited remotely?
CVE-2021-21878 requires authenticated access, meaning an attacker must first gain valid credentials to exploit the vulnerability.
What is local file inclusion in the context of CVE-2021-21878?
In the context of CVE-2021-21878, local file inclusion allows an attacker to access and potentially manipulate files on the server by crafting specific HTTP requests.