CVE-2021-37913: HGiga OAKlouds - Command Injection-2
The HGiga OAKlouds mobile portal does not filter special characters of the IPv6 Gateway parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HGiga OAKlouds OAKSv2to a version that resolves this vulnerability.Fixed in OAKlouds-network-2.0-3 - Upgrade
Upgrade
HGiga OAKlouds OAKSv3to a version that resolves this vulnerability.Fixed in OAKlouds-network-2.0-3
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37913?
CVE-2021-37913 has a high severity level due to its potential for remote command injection.
How do I fix CVE-2021-37913?
To fix CVE-2021-37913, update the HGiga OAKlouds portal to the latest version provided by the vendor.
What systems are affected by CVE-2021-37913?
CVE-2021-37913 affects HGiga OAKlouds portal versions 2.0-2 and 3.0-2.
Can CVE-2021-37913 be exploited without login?
Yes, CVE-2021-37913 can be exploited remotely without requiring user login.
What impact does CVE-2021-37913 have on systems?
CVE-2021-37913 allows attackers to execute arbitrary commands on the system, potentially compromising its security.