CVE-2021-26747: OS Command Injection
Published Feb 18, 2021
·Updated
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
Affected Software
4 affected components
netis-systems Wf2780 Firmware=2.3.40404
netis-systems Wf2780
netis-systems Wf2411 Firmware=1.1.29629
netis-systems Wf2411
Event History
Feb 18, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Netis WF2780 and WF2411 devices?
The vulnerability ID for Netis WF2780 and WF2411 devices is CVE-2021-26747.
2
How severe is CVE-2021-26747?
CVE-2021-26747 has a severity rating of 9.8 (Critical).
3
What is the impact of CVE-2021-26747?
CVE-2021-26747 allows Shell Metacharacter Injection into the ping command, leading to remote code execution.
4
Which devices are affected by CVE-2021-26747?
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices are affected by CVE-2021-26747.
5
How can I fix CVE-2021-26747?
At this time, there is no official fix or patch available for CVE-2021-26747. It is recommended to follow the vendor's website for updates.