CVE-2021-21884: OS Command Injection
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21884?
CVE-2021-21884 is rated as a critical severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2021-21884?
To fix CVE-2021-21884, update the Lantronix PremierWave 2050 firmware to the latest version provided by the vendor.
What are the impacts of CVE-2021-21884?
The impacts of CVE-2021-21884 include the possibility of unauthorized command execution on the affected device.
Who is affected by CVE-2021-21884?
CVE-2021-21884 affects users of the Lantronix PremierWave 2050 running firmware version 8.9.0.0-r4.
Can CVE-2021-21884 be exploited remotely?
Yes, CVE-2021-21884 can be exploited remotely through an authenticated HTTP request.