CVE-2021-42912
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp0509 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 01 A | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp2610 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 01 B | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp2520 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 02 B | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp2510 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 04 B | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp2617 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 04 F | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version rp2560 |
| Running on/with | Platform Versions |
|---|---|
Fiberhome An5506 04 G2g | All versions |
References (6)
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.