First published: Fri Jun 25 2021(Updated: )
In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic scripts while authenticated as a low privilege user to trigger this vulnerability.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weidmueller Ie-wl-bl-ap-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wl-bl-ap-cl-eu | ||
Weidmueller Ie-wlt-bl-ap-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-bl-ap-cl-eu | ||
Weidmueller Ie-wl-bl-ap-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wl-bl-ap-cl-us | ||
Weidmueller Ie-wlt-bl-ap-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-bl-ap-cl-us | ||
Weidmueller Ie-wl-vl-ap-br-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wl-vl-ap-br-cl-eu | ||
Weidmueller Ie-wlt-vl-ap-br-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-vl-ap-br-cl-eu | ||
Weidmueller Ie-wl-vl-ap-br-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wl-vl-ap-br-cl-us | ||
Weidmueller Ie-wlt-vl-ap-br-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-vl-ap-br-cl-us | ||
Weidmueller Ie-wl-bl-ap-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-bl-ap-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wl-bl-ap-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-bl-ap-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wl-vl-ap-br-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-vl-ap-br-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wl-vl-ap-br-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-vl-ap-br-cl-us Firmware | <=1.11.10 |
For IE-WL(T)-BL-AP-CL-XX versions V1.16.21 (Build 21010513) and greater are fixed. For IE-WL(T)-VL-AP-CL-XX versions V1.11.13 (Build 21010513) and greater are fixed.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33531 is a vulnerability in Weidmueller Industrial WLAN devices that allows for the creation of custom diagnostic scripts using an undocumented encryption password.
CVE-2021-33531 is classified as a critical vulnerability with a severity score of 8.8.
Multiple versions of Weidmueller Industrial WLAN devices firmware up to and including 1.16.18 are affected by CVE-2021-33531.
There is currently no known fix for CVE-2021-33531. It is recommended to follow the vendor's advisories and apply any patches or updates as they become available.
You can find more information about CVE-2021-33531 on the VDE CERT website at the following link: https://cert.vde.com/en-us/advisories/vde-2021-026