CVE-2021-33535: WEIDMUELLER: WLAN devices affected by exploitable format string vulnerability
In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iwconsole coniowritestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33535?
CVE-2021-33535 is a format string vulnerability that exists in the iw_console conio_writestr functionality of Weidmueller Industrial WLAN devices.
How severe is CVE-2021-33535?
CVE-2021-33535 has a severity rating of 8.8 (high).
Which versions of Weidmueller Industrial WLAN devices are affected by CVE-2021-33535?
Multiple versions of Weidmueller Industrial WLAN devices are affected including Ie-wl-bl-ap-cl-eu Firmware up to version 1.16.18 and Ie-wl-bl-ap-cl-eu Firmware up to version 1.11.10.
How does CVE-2021-33535 work?
CVE-2021-33535 occurs when a specially crafted time server entry causes an overflow of the time server buffer in the affected devices, leading to remote code execution.
Where can I find more information about CVE-2021-33535?
More information about CVE-2021-33535 can be found at the following reference: [VDE-2021-026](https://cert.vde.com/en-us/advisories/vde-2021-026).