ZeroHour

CVE-2021-40858

PoC ×3
CVSS 3.1
4.9 medium
EPSS
2%p83
Published
()
Modified
Description

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

Vendors
auerswald
Products
compact 5500r ip firmware, compact 5200r ip firmware, compact 5000r ip firmware, compact 4000 ip firmware, commander 6000r ip firmware, commander 6000rx ip firmware, commander business\(19\"\) ip firmware, commander basic.2\(19\"\) ip firmware, compact 5010 voip ip firmware, compact 5020 voip ip firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.