CVE-2021-47745: Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection via Firmware Upgrade
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fwurl' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47745?
CVE-2021-47745 is considered to be a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2021-47745?
To mitigate CVE-2021-47745, ensure that your CTM-200 firmware is updated to the latest version provided by Cypress Solutions.
What type of vulnerability is CVE-2021-47745?
CVE-2021-47745 is an authenticated command injection vulnerability in the firmware upgrade script.
Who is affected by CVE-2021-47745?
CVE-2021-47745 affects users of Cypress Solutions CTM-200 version 2.7.1.
How can attackers exploit CVE-2021-47745?
Attackers can exploit CVE-2021-47745 by injecting malicious commands through the 'fw_url' parameter in the ctm-config-upgrade.sh script.