CVE-2021-21888
9.1
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.89% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-12-22 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| lantronix | premierwave 2050 |
| lantronix | premierwave 2050 firmware |
References
→ the Explorer · watch your stack · NVD