Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-100345
HistoryDec 12, 2021 - 12:00 a.m.

Gryphon Tower Command Injection Vulnerability (CNVD-2021-100345)

2021-12-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
gryphon tower
command injection
wireless router
vulnerability
cnvd-2021-100345
controller server
remote attacker
malicious packets
root access

EPSS

0.002

Percentile

58.8%

A command injection vulnerability exists in Gryphon Tower, a wireless router from Gryphon, which stems from a failure to properly filter user input for special characters, commands, etc. in the parameters of operation 10 in the controller_server service on the router. An unauthenticated, remote attacker could use the vulnerability to send specially crafted malicious packets to execute commands on the device as root.

EPSS

0.002

Percentile

58.8%

Related for CNVD-2021-100345