CVE-2021-21880: Path Traversal
A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21880?
CVE-2021-21880 is considered to have high severity due to its potential for local file inclusion through a directory traversal attack.
How do I fix CVE-2021-21880?
To fix CVE-2021-21880, update the Lantronix PremierWave 2050 firmware to version 8.9.0.0R4 or later.
What platforms are affected by CVE-2021-21880?
CVE-2021-21880 affects the Lantronix PremierWave 2050 firmware version 8.9.0.0R4.
What type of attack can exploit CVE-2021-21880?
CVE-2021-21880 can be exploited through a specially-crafted HTTP request to perform a directory traversal attack.
Are authenticated users required to exploit CVE-2021-21880?
Yes, exploitation of CVE-2021-21880 requires the attacker to make an authenticated HTTP request.