CVE-2021-21896: Path Traversal
A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file deletion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21896?
CVE-2021-21896 is considered a critical vulnerability due to its potential for arbitrary file deletion.
How do I fix CVE-2021-21896?
To mitigate CVE-2021-21896, upgrade to a newer firmware version that addresses this vulnerability.
Who is affected by CVE-2021-21896?
CVE-2021-21896 affects users running Lantronix PremierWave 2050 Firmware version 8.9.0.0-R4.
What type of attack does CVE-2021-21896 enable?
CVE-2021-21896 enables an attacker to perform a directory traversal attack leading to arbitrary file deletion through crafted HTTP requests.
Is authentication required to exploit CVE-2021-21896?
Yes, an attacker must be authenticated to send HTTP requests that exploit CVE-2021-21896.