CVE-2021-40858

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/12/2021
Last modified:
04/01/2022

Description

Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:auerswald:compact_5500r_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:compact_5500r_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:compact_5200r_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:compact_5200r_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:compact_5000r_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:compact_5000r_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:compact_4000_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:compact_4000r_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:commander_6000r_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:commander_6000r_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:commander_6000rx_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:commander_6000rx_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:commander_business\(19\"\)_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)
cpe:2.3:h:auerswald:commander_business\(19\"\)_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:auerswald:commander_basic.2\(19\"\)_ip_firmware:*:*:*:*:*:*:*:* 8.0b (including)