CVE-2021-38169: Command Injection
Published Aug 7, 2021
·Updated
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/apifunct.py.
Affected Software
1 affected component
Roxy-WI Roxy-wi<=5.2.2.0
Event History
Aug 7, 2021
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38169?
CVE-2021-38169 is classified as a high-severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2021-38169?
To fix CVE-2021-38169, upgrade Roxy-WI to version 5.2.2.1 or later where the vulnerability is patched.
3
What systems are affected by CVE-2021-38169?
CVE-2021-38169 affects Roxy-WI versions up to and including 5.2.2.0.
4
What kind of attack is possible with CVE-2021-38169?
CVE-2021-38169 allows attackers to exploit command injection vulnerabilities to execute arbitrary commands on the server.
5
Is CVE-2021-38169 actively being exploited?
There have been reports indicating that CVE-2021-38169 is being actively targeted in the wild.