Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-01602
HistoryNov 21, 2021 - 12:00 a.m.

Lantronix PremierWave 2050 OS Command Injection Vulnerability

2021-11-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
lantronix
premierwave 2050
os command injection
vulnerability
diagnostics:ping
authenticated
http request
arbitrary command execution

EPSS

0.003

Percentile

70.2%

The Lantronix PremierWave 2050 is an embedded enterprise Wi-Fi module from Lantronix, Inc. The Lantronix PremierWave 2050 in version 8.9.0.0R4 is vulnerable to OS command injection, which stems from a Web Manager Diagnostics:Ping feature that fails to properly filter special characters, commands, etc. An authenticated attacker could use this vulnerability to potentially cause arbitrary command execution via a specially crafted HTTP request.

EPSS

0.003

Percentile

70.2%