CVE-2021-38306: Command Injection
Network Attached Storage on LG N1T1 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38306?
The severity of CVE-2021-38306 is critical with a score of 9.8.
How does CVE-2021-38306 affect LG N1T1 devices?
CVE-2021-38306 affects LG N1T1 devices by allowing an unauthenticated attacker to gain root access.
How can an attacker exploit CVE-2021-38306?
An attacker can exploit CVE-2021-38306 through OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
Which software versions of LG N1T1 are affected by CVE-2021-38306?
CVE-2021-38306 affects LG N1T1 devices with the firmware version N1T1_Firmware and does not affect LG N1T1 or LG N1T1DD1 devices.
Is there a fix available for CVE-2021-38306?
No fix is currently available for CVE-2021-38306. It is recommended to apply any relevant security patches or updates provided by LG.