CVE-2021-34602
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.
Affected (8)
Products: Bender: Cc612 Firmware, Icc15xx Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 |
| Running on/with | Platform Versions |
|---|---|
Bender Cc612 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 |
| Running on/with | Platform Versions |
|---|---|
Bender Cc613 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.