← Back

CVE-2021-42912

nvd nist
Published: Dec 16, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

Affected (8)

6 products
An5506 01 A Firmware
An5506 01 B Firmware
An5506 02 B Firmware
An5506 04 B Firmware
An5506 04 F Firmware
Aan5506 04 G2g Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp0509
Running on/withPlatform Versions
Fiberhome
An5506 01 A
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2610
Running on/withPlatform Versions
Fiberhome
An5506 01 B
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Fiberhome
Version rp2520
Version rp2521
Version rp2603
Running on/withPlatform Versions
Fiberhome
An5506 02 B
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2510
Running on/withPlatform Versions
Fiberhome
An5506 04 B
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2617
Running on/withPlatform Versions
Fiberhome
An5506 04 F
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2560
Running on/withPlatform Versions
Fiberhome
An5506 04 G2g
All versions

References (6)

Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.