Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-100348
HistoryDec 12, 2021 - 12:00 a.m.

Gryphon Tower Command Injection Vulnerability (CNVD-2021-100348)

2021-12-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
gryphon inc
wireless router
command injection
security vulnerability
remote attacker
root access
cnvd-2021-100348

EPSS

0.002

Percentile

58.8%

Gryphon Tower is a wireless router from Gryphon, Inc. A command injection vulnerability exists in Gryphon Tower, which stems from the failure to properly filter user input for special characters, commands, etc. in the controller_server service on the router, which could be exploited by a remote, unauthenticated attacker to send specially crafted malicious packets to execute commands on the device as root.

EPSS

0.002

Percentile

58.8%

Related for CNVD-2021-100348