First published: Thu Apr 29 2021(Updated: )
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chinamobile An Lianbao Wf-1 Firmware | =1.0.1 | |
Chinamobile An Lianbao Wf-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-30230 is Critical with a CVSS score of 9.8.
CVE-2021-30230 allows remote attackers to execute arbitrary commands on the China Mobile An Lianbao WF-1 router.
An attacker can exploit CVE-2021-30230 by sending shell metacharacters in the zonename parameter of the api/ZRFirmware/set_time_zone interface.
Yes, China Mobile An Lianbao WF-1 router version 1.0.1 is affected by CVE-2021-30230.
To mitigate the vulnerability in China Mobile An Lianbao WF-1 router version 1.0.1, it is recommended to apply the latest security patches or updates provided by the vendor.