CVE-2021-33528: WEIDMUELLER: WLAN devices affected by privilege escalation vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iwconsole functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33528?
CVE-2021-33528 is a privilege escalation vulnerability in Weidmueller Industrial WLAN devices.
What is the severity of CVE-2021-33528?
The severity of CVE-2021-33528 is critical with a CVSS score of 8.8.
How can an attacker exploit CVE-2021-33528?
An attacker can exploit CVE-2021-33528 by using a specially crafted menu selection string to escape from the restricted console and gain system access as the root user.
Which versions of Weidmueller Industrial WLAN devices are affected by CVE-2021-33528?
Multiple versions of Weidmueller Industrial WLAN devices are affected by CVE-2021-33528, including firmware versions up to and including 1.16.18 for various models.
Is there a fix available for CVE-2021-33528?
To mitigate the vulnerability, it is recommended to update the affected devices to a patched version of the firmware provided by Weidmueller.