CVE-2021-31573

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
06/02/2023
Last modified:
26/03/2025

Description

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mediatek:en7580_firmware:*:*:*:*:*:*:*:* tlm7.3.275.0-82 (excluding)
cpe:2.3:h:mediatek:en7580:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:en7528_firmware:*:*:*:*:*:*:*:* tlm7.3.275.0-82 (excluding)
cpe:2.3:h:mediatek:en7528:-:*:*:*:*:*:*:*