First published: Tue Aug 24 2021(Updated: )
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lg N1t1 Firmware | ||
LG N1T1 | ||
Lg N1t1dd1 | ||
All of | ||
Lg N1t1 Firmware | ||
Any of | ||
LG N1T1 | ||
Lg N1t1dd1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38306 is critical with a score of 9.8.
CVE-2021-38306 affects LG N1T1 devices by allowing an unauthenticated attacker to gain root access.
An attacker can exploit CVE-2021-38306 through OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
CVE-2021-38306 affects LG N1T1 devices with the firmware version N1T1_Firmware and does not affect LG N1T1 or LG N1T1DD1 devices.
No fix is currently available for CVE-2021-38306. It is recommended to apply any relevant security patches or updates provided by LG.