Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-04973
HistoryDec 28, 2021 - 12:00 a.m.

Lantronix PremierWave 2050 OS Command Injection Vulnerability (CNVD-2022-04973)

2021-12-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
lantronix
premierwave 2050
os command injection
vulnerability
embedded
wi-fi module
web manager
sslgeneratecsr
arbitrary command execution
http request

EPSS

0.003

Percentile

70.2%

The PremierWave 2050 is an embedded Wi-Fi module manufactured by Lantronix.The Web Manager SslGenerateCSR feature of the Lantronix PremierWave 2050 8.9.0.0R4 is vulnerable to OS command injection, which can be exploited by attackers to cause arbitrary command execution with the help of specially crafted HTTP request to cause arbitrary command execution.

EPSS

0.003

Percentile

70.2%