← Back

CVE-2021-38611

nvd nist
Published: Aug 24, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.

Affected (1)

1 product
Remkon Device Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0.0.0

Timeline

No history available yet.