First published: Thu Apr 29 2021(Updated: )
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chinamobile An Lianbao Wf-1 Firmware | =1.0.1 | |
Chinamobile An Lianbao Wf-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-30232.
The severity of CVE-2021-30232 is critical with a severity value of 9.8.
The affected software of CVE-2021-30232 is China Mobile An Lianbao WF-1 router 1.0.1.
CVE-2021-30232 allows remote attackers to execute arbitrary commands via shell metacharacters in a specific parameter of the affected software.
Yes, there are references available for CVE-2021-30232. You can find them at the following links: [Link 1](http://iot.10086.cn/?l=en-us), [Link 2](https://github.com/pokerfacett/MY_REQUEST/blob/master/China%20Mobile%20An%20Lianbao%20WF-1%20router%20Command%20Injection6.md), [Link 3](https://www.cnvd.org.cn/flaw/show/CNVD-2021-03520).