CVE-2021-33531: WEIDMUELLER: WLAN devices affected by Hard-coded Credentials vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic scripts while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33531?
CVE-2021-33531 is a vulnerability in Weidmueller Industrial WLAN devices that allows for the creation of custom diagnostic scripts using an undocumented encryption password.
How severe is CVE-2021-33531?
CVE-2021-33531 is classified as a critical vulnerability with a severity score of 8.8.
Which software versions are affected by CVE-2021-33531?
Multiple versions of Weidmueller Industrial WLAN devices firmware up to and including 1.16.18 are affected by CVE-2021-33531.
How can I fix CVE-2021-33531?
There is currently no known fix for CVE-2021-33531. It is recommended to follow the vendor's advisories and apply any patches or updates as they become available.
Where can I find more information about CVE-2021-33531?
You can find more information about CVE-2021-33531 on the VDE CERT website at the following link: https://cert.vde.com/en-us/advisories/vde-2021-026