CVE-2021-37289: High severity planex mzk-dp150n firmware vulnerability
Published Aug 22, 2022
·Updated
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etcro/web/syscmd.asp.
Affected Software
3 affected components
PLANEX Mzk-dp150n Firmware=1.42
PLANEX Mzk-dp150n Firmware=1.43
PLANEX MZK-DP150N
Event History
Aug 22, 2022
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-37289?
CVE-2021-37289 has been classified with a medium severity rating due to its potential for unauthorized command execution as root.
2
How do I fix CVE-2021-37289?
To remediate CVE-2021-37289, upgrade the Planex MZK-DP150N firmware to a version higher than 1.43.
3
What are the affected versions of CVE-2021-37289?
CVE-2021-37289 affects Planex MZK-DP150N firmware versions 1.42 and 1.43.
4
What is the nature of the vulnerability described in CVE-2021-37289?
CVE-2021-37289 involves insecure permissions in the administration interface that allow attackers to execute system commands.
5
Who is impacted by CVE-2021-37289?
Users of the Planex MZK-DP150N router running firmware versions 1.42 or 1.43 are vulnerable to CVE-2021-37289.