CVE-2021-3149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
22/02/2021
Last modified:
25/07/2022

Description

On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netshieldcorp:nano_25_firmware:10.2.18:*:*:*:*:*:*:*
cpe:2.3:h:netshieldcorp:nano_25:-:*:*:*:*:*:*:*