peter bassill · operator
$ cve CVE-2021-35978 JSON

CVE-2021-35978

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute arbitrary code on the controller including overwriting firmware, adding/removing users, disabling the internal firewall, etc.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.68% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2021-12-10
Last modified2026-06-17

Affected (18)

VendorProduct
digitransport dr64
digitransport dr64 firmware
digitransport sr44
digitransport sr44 firmware
digitransport vc74
digitransport vc74 firmware
digitransport wr11
digitransport wr11 firmware
digitransport wr11 xt
digitransport wr11 xt firmware
digitransport wr21
digitransport wr21 firmware
digitransport wr31
digitransport wr31 firmware
digitransport wr41
digitransport wr41 firmware
digitransport wr44
digitransport wr44 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD