CVE-2021-21884
9.1
CRITICAL · CVSS 3.1 · EPSS 5.3% (pctl 92)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 5.27% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-12-22 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| lantronix | premierwave 2050 |
| lantronix | premierwave 2050 firmware |
References
→ the Explorer · watch your stack · NVD