← Back

CVE-2021-35978

nvd nist
Published: Dec 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

Affected (11)

9 products
Transport Dr64 Firmware
Transport Sr44 Firmware
Transport Vc74 Firmware
Transport Wr11 Firmware
Transport Wr11 Xt Firmware
Transport Wr21 Firmware
Transport Wr31 Firmware
Transport Wr41 Firmware
Transport Wr44 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.4.9
Running on/withPlatform Versions
Digi
Transport Dr64
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Digi
Transport Sr44
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 5.2.4.9
Running on/withPlatform Versions
Digi
Transport Vc74
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.2.1.3
Running on/withPlatform Versions
Digi
Transport Wr11
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.2.1.3
Running on/withPlatform Versions
Digi
Transport Wr11 Xt
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.2.1.3
Running on/withPlatform Versions
Digi
Transport Wr21
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.2.1.3
Running on/withPlatform Versions
Digi
Transport Wr31
All versions
Configuration H
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Digi
From 5.0.0.0 to 5.2.4.6
From 6.0.0.0 to 6.1.3.5
From 8.0.0.0 to 8.3.1.2
Running on/withPlatform Versions
Digi
Transport Wr41
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.3.1.2
Running on/withPlatform Versions
Digi
Transport Wr44
Version v2

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.