Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-01599
HistoryNov 21, 2021 - 12:00 a.m.

Lantronix PremierWave 2050 OS Command Injection Vulnerability (CNVD-2022-01599)

2021-11-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
lantronix
premierwave 2050
command injection
vulnerability
web manager
wireless network scanner
authentication
arbitrary command execution
http request

EPSS

0.969

Percentile

99.7%

The Lantronix PremierWave 2050 is an embedded enterprise Wi-Fi module from Lantronix, Inc. The Lantronix PremierWave 2050 in version 8.9.0.0R4 contains a security vulnerability that originates when the Web Manager wireless network scanner feature fails to properly filter special characters, commands, etc. An authenticated attacker could use this vulnerability to potentially cause arbitrary command execution via a specially crafted HTTP request.

EPSS

0.969

Percentile

99.7%