← Back

CVE-2021-42912

nvd nist
Published: Dec 16, 2021Modified: Jul 9, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

Affected (8)

6 products
An5506 01 A Firmware
An5506 01 B Firmware
An5506 02 B Firmware
An5506 04 B Firmware
An5506 04 F Firmware
Aan5506 04 G2g Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp0509
Running on/withPlatform Versions
Fiberhome
An5506 01 A
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2610
Running on/withPlatform Versions
Fiberhome
An5506 01 B
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Fiberhome
Version rp2520
Version rp2521
Version rp2603
Running on/withPlatform Versions
Fiberhome
An5506 02 B
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2510
Running on/withPlatform Versions
Fiberhome
An5506 04 B
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2617
Running on/withPlatform Versions
Fiberhome
An5506 04 F
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version rp2560
Running on/withPlatform Versions
Fiberhome
An5506 04 G2g
All versions

Timeline

No history available yet.