CVE-2021-42165: OS Command Injection
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42165?
CVE-2021-42165 has been assigned a high severity rating due to its potential for remote authenticated users to gain root access.
How do I fix CVE-2021-42165?
To mitigate CVE-2021-42165, ensure that all firmware updates are applied, particularly those addressing the specific vulnerability in the device.
Who is affected by CVE-2021-42165?
CVE-2021-42165 affects users of the MitraStar GPT-2541GNAC-N1 router running firmware version br_g3.5_100vnz0b33.
What causes CVE-2021-42165?
CVE-2021-42165 is caused by incorrect sanitization of the 'path' parameter, allowing command execution vulnerabilities.
Is CVE-2021-42165 exploitable remotely?
Yes, CVE-2021-42165 can be exploited by remote authenticated users to execute commands that may grant root access.