ZeroHour

CVE-2021-42912

CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
Modified
Description

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

Vendors
fiberhome
Products
an5506-01-a firmware, an5506-01-b firmware, an5506-02-b firmware, an5506-04-b firmware, an5506-04-f firmware, aan5506-04-g2g firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.