CVE-2021-4039: OS Command Injection
Published Mar 1, 2022
·Updated
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
Affected Software
2 affected components
Zyxel Nwa1100-nh Firmware<2.12\(aasi.3\)c0
Zyxel NWA1100-NH
Remediation
Event History
Mar 1, 2022
CVE Published
via MITRE·06:40 AM
Data Sourced
via MITRE·06:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-4039?
CVE-2021-4039 has a high severity rating due to its ability to allow attackers to execute arbitrary OS commands.
2
How do I fix CVE-2021-4039?
To fix CVE-2021-4039, you should update the Zyxel NWA-1100-NH firmware to version 2.12(aasi.3)c0 or later.
3
What devices are affected by CVE-2021-4039?
CVE-2021-4039 affects the Zyxel NWA-1100-NH firmware versions prior to 2.12(aasi.3)c0.
4
Can CVE-2021-4039 lead to data theft?
Yes, CVE-2021-4039 can potentially lead to data theft as it allows execution of arbitrary commands on the device.
5
What are the consequences of CVE-2021-4039 exploitation?
Exploitation of CVE-2021-4039 can allow unauthorized access and control over the affected Zyxel NWA-1100-NH devices.