First published: Thu Mar 25 2021(Updated: )
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek Xpon Rtl9601d Software Development Kit | =1.9 | |
Realtek xPON RTL9601D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27372 is a vulnerability in Realtek xPON RTL9601D SDK 1.9 that allows attackers to gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
CVE-2021-27372 has a severity rating of 9.8 (Critical).
Realtek xPON RTL9601D SDK 1.9 is affected by CVE-2021-27372.
Passwords are stored in plaintext in Realtek xPON RTL9601D SDK 1.9.
Attackers can exploit CVE-2021-27372 by using the build-in network monitoring tool to gain access to the device with root permissions and execute arbitrary commands.