First published: Sun Mar 21 2021(Updated: )
applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenWrt OpenWrt | =19.07.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28961 is a vulnerability in the DDNS package for OpenWrt 19.07 that allows remote authenticated users to inject arbitrary commands via POST requests.
The severity of CVE-2021-28961 is high with a CVSS score of 8.8.
Remote authenticated users can exploit CVE-2021-28961 by sending malicious POST requests to the affected application.
Yes, a patch has been released by OpenWrt. Please refer to the provided references for more information.
CVE-2021-28961 is categorized under CWE-78, which is Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').