First published: Fri Jun 25 2021(Updated: )
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Weidmueller Ie-wl-bl-ap-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wl-bl-ap-cl-eu | ||
Weidmueller Ie-wlt-bl-ap-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-bl-ap-cl-eu | ||
Weidmueller Ie-wl-bl-ap-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wl-bl-ap-cl-us | ||
Weidmueller Ie-wlt-bl-ap-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-bl-ap-cl-us | ||
Weidmueller Ie-wl-vl-ap-br-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wl-vl-ap-br-cl-eu | ||
Weidmueller Ie-wlt-vl-ap-br-cl-eu Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-vl-ap-br-cl-eu | ||
Weidmueller Ie-wl-vl-ap-br-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wl-vl-ap-br-cl-us | ||
Weidmueller Ie-wlt-vl-ap-br-cl-us Firmware | <=1.16.18 | |
Weidmueller Ie-wlt-vl-ap-br-cl-us | ||
Weidmueller Ie-wl-bl-ap-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-bl-ap-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wl-bl-ap-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-bl-ap-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wl-vl-ap-br-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-vl-ap-br-cl-eu Firmware | <=1.11.10 | |
Weidmueller Ie-wl-vl-ap-br-cl-us Firmware | <=1.11.10 | |
Weidmueller Ie-wlt-vl-ap-br-cl-us Firmware | <=1.11.10 |
For IE-WL(T)-BL-AP-CL-XX versions V1.16.21 (Build 21010513) and greater are fixed. For IE-WL(T)-VL-AP-CL-XX versions V1.11.13 (Build 21010513) and greater are fixed.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33534.
The severity of CVE-2021-33534 is critical with a CVSS score of 7.2.
Weidmueller Industrial WLAN devices with the following firmware versions are affected by CVE-2021-33534: Ie-wl-bl-ap-cl-eu Firmware up to version 1.16.18, Ie-wlt-bl-ap-cl-eu Firmware up to version 1.16.18, Ie-wl-bl-ap-cl-us Firmware up to version 1.16.18, Ie-wlt-bl-ap-cl-us Firmware up to version 1.16.18, Ie-wl-vl-ap-br-cl-eu Firmware up to version 1.16.18, Ie-wlt-vl-ap-br-cl-eu Firmware up to version 1.16.18, Ie-wl-vl-ap-br-cl-us Firmware up to version 1.16.18, Ie-wlt-vl-ap-br-cl-us Firmware up to version 1.16.18, Ie-wl-bl-ap-cl-eu Firmware up to version 1.11.10, Ie-wlt-bl-ap-cl-eu Firmware up to version 1.11.10, Ie-wl-bl-ap-cl-us Firmware up to version 1.11.10, Ie-wlt-bl-ap-cl-us Firmware up to version 1.11.10, Ie-wl-vl-ap-br-cl-eu Firmware up to version 1.11.10, Ie-wlt-vl-ap-br-cl-eu Firmware up to version 1.11.10, Ie-wl-vl-ap-br-cl-us Firmware up to version 1.11.10, Ie-wlt-vl-ap-br-cl-us Firmware up to version 1.11.10.
CVE-2021-33534 is a command injection vulnerability in Weidmueller Industrial WLAN devices that allows an attacker to execute arbitrary system commands and gain full control of the device by manipulating the hostname configuration.
A fix for CVE-2021-33534 is not mentioned in the provided information, so it is recommended to follow the guidance provided by Weidmueller or the vendor to mitigate the vulnerability.