CVE-2021-33532: WEIDMUELLER: WLAN devices affected by OS Command Injection vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iwwebs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this Weidmueller Industrial WLAN vulnerability?
The vulnerability ID of this Weidmueller Industrial WLAN vulnerability is CVE-2021-33532.
What is the severity of CVE-2021-33532?
The severity of CVE-2021-33532 is critical, with a severity value of 8.8.
What software versions are affected by CVE-2021-33532?
The Weidmueller Industrial WLAN devices with firmware versions up to 1.16.18 are affected.
What is the CWE category for CVE-2021-33532?
The CWE categories for CVE-2021-33532 are CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')).
How can I fix CVE-2021-33532?
Apply the latest firmware update provided by Weidmueller to fix CVE-2021-33532.