First published: Thu Apr 29 2021(Updated: )
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chinamobile An Lianbao Wf-1 Firmware | =1.0.1 | |
Chinamobile An Lianbao Wf-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-30233 is critical with a severity value of 9.8.
CVE-2021-30233 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter of the api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1.
The affected software of CVE-2021-30233 is China Mobile An Lianbao WF-1 router 1.0.1.
Yes, there are known references for CVE-2021-30233. They can be found at the following links: [http://iot.10086.cn/?l=en-us](http://iot.10086.cn/?l=en-us), [https://github.com/pokerfacett/MY_REQUEST/blob/master/China%20Mobile%20An%20Lianbao%20WF-1%20router%20Command%20Injection8.md](https://github.com/pokerfacett/MY_REQUEST/blob/master/China%20Mobile%20An%20Lianbao%20WF-1%20router%20Command%20Injection8.md), [https://www.cnvd.org.cn/flaw/show/CNVD-2021-03520](https://www.cnvd.org.cn/flaw/show/CNVD-2021-03520).
CVE-2021-30233 falls under the Common Weakness Enumeration (CWE) category 78.