CVE-2021-37912: HGiga OAKlouds - Command Injection-1
The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OAKlouds OAKSv2to a version that resolves this vulnerability.Fixed in OAKlouds-network-2.0-3 - Upgrade
Upgrade
OAKlouds OAKSv3to a version that resolves this vulnerability.Fixed in OAKlouds-network-2.0-3
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37912?
CVE-2021-37912 has a high severity level due to the potential for remote command injection.
How do I fix CVE-2021-37912?
To fix CVE-2021-37912, update the HGiga OAKlouds portal to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2021-37912?
The impact of CVE-2021-37912 includes the possibility of remote attackers executing arbitrary commands on the system.
Which versions of HGiga OAKlouds are affected by CVE-2021-37912?
CVE-2021-37912 affects HGiga OAKlouds portal versions between 2.0 and 2.0 and between 3.0 and 3.0.
Who can exploit CVE-2021-37912?
Remote attackers can exploit CVE-2021-37912 without needing to log into the system.