CVE-2021-33530: WEIDMUELLER: WLAN devices affected by OS Command Injection vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33530.
What is the severity of CVE-2021-33530?
CVE-2021-33530 has a severity rating of 8.8, which is considered critical.
Which software versions are affected by CVE-2021-33530?
The following Weidmueller Industrial WLAN devices firmware versions are affected: Ie-wl-bl-ap-cl-eu firmware up to and including 1.16.18, Ie-wlt-bl-ap-cl-eu firmware up to and including 1.16.18, Ie-wl-bl-ap-cl-us firmware up to and including 1.16.18, Ie-wlt-bl-ap-cl-us firmware up to and including 1.16.18, Ie-wl-vl-ap-br-cl-eu firmware up to and including 1.16.18, Ie-wlt-vl-ap-br-cl-eu firmware up to and including 1.16.18, Ie-wl-vl-ap-br-cl-us firmware up to and including 1.16.18, and Ie-wlt-vl-ap-br-cl-us firmware up to and including 1.16.18.
How can I exploit CVE-2021-33530?
In order to exploit CVE-2021-33530, an attacker would need to craft a specially designed diagnostic script file and have it executed on the vulnerable Weidmueller Industrial WLAN device.
Is there a fix available for CVE-2021-33530?
At the moment, there does not appear to be a fix available for CVE-2021-33530. It is recommended to follow the guidance provided by the vendor and stay informed about any updates or patches that may be released.