CVE-2021-21883: OS Command Injection
An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21883?
CVE-2021-21883 is rated as a critical vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2021-21883?
To fix CVE-2021-21883, it is recommended to update the firmware to version 8.9.0.0R5 or later from Lantronix.
What systems are affected by CVE-2021-21883?
CVE-2021-21883 affects the Lantronix PremierWave 2050 firmware version 8.9.0.0R4.
What exploits are possible with CVE-2021-21883?
Exploiting CVE-2021-21883 allows an attacker to execute arbitrary operating system commands on the vulnerable device.
Is authentication required to exploit CVE-2021-21883?
Yes, an attacker needs to make an authenticated HTTP request to successfully exploit CVE-2021-21883.