CVE-2021-39280: Critical severity korenix jetwave 2212s firmware vulnerability
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39280?
CVE-2021-39280 is a vulnerability that allows authenticated users to execute arbitrary code as root on certain Korenix JetWave devices via /syscmd.asp.
Which Korenix JetWave devices are affected by CVE-2021-39280?
CVE-2021-39280 affects Korenix JetWave 2212X (before 1.9.1), 2212S (before 1.9.1), 2212G (before 1.8), 3220 V3 (before 1.5.1), 3420 V3 (before 1.5.1), and 2311 (through 2022-01-31).
How severe is CVE-2021-39280?
CVE-2021-39280 has a severity rating of 8.8 (critical).
How can I fix CVE-2021-39280?
To fix CVE-2021-39280, users should update their Korenix JetWave devices to the latest firmware versions: 2212X 1.9.1, 2212S 1.9.1, 2212G 1.8, 3220 V3 1.5.1, 3420 V3 1.5.1, and ensure that 2311 firmware is updated to a version released after January 31, 2022.
Where can I find more information about Korenix JetWave devices?
You can find more information about Korenix JetWave devices on the Korenix website.