First published: Thu Aug 12 2021(Updated: )
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quectel EG25-G Firmware | <=202006130814 | |
Quectel EG25-G Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31698 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2021-31698, update the Quectel EG25-G firmware to a version later than 202006130814.
CVE-2021-31698 affects Quectel EG25-G devices running firmware version 202006130814 or earlier.
CVE-2021-31698 is a remote code execution vulnerability that can be exploited via AT commands.
Exploitation of CVE-2021-31698 can lead to unauthorized access and execution of arbitrary code on the device.