← Back

CVE-2021-39280

nvd nist
Published: Feb 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.

Affected (6)

6 products
Jetwave 2212s Firmware
Jetwave 2212g Firmware
Jetwave 2311 Firmware
Jetwave 3220 Firmware
Jetwave 3420 Firmware
Jetwave 2212x Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.9.1
Running on/withPlatform Versions
Korenix
Jetwave 2212s
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.8
Running on/withPlatform Versions
Korenix
Jetwave 2212g
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.2
Running on/withPlatform Versions
Korenix
Jetwave 2311
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.5.1
Running on/withPlatform Versions
Korenix
Jetwave 3220
Version 3
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.5.1
Running on/withPlatform Versions
Korenix
Jetwave 3420
Version 3
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.9.1
Running on/withPlatform Versions
Korenix
Jetwave 2212x
All versions

References (4)

Timeline

No history available yet.