peter bassill · operator
$ cve CVE-2021-40859 JSON

CVE-2021-40859 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 72% (pctl 99)

Patch early

A public exploit exists.

Description

Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS71.98% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2021-12-07
Last modified2026-06-17

Affected (2)

VendorProduct
auerswaldcompact 5500r
auerswaldcompact 5500r firmware

Public exploits

SourceTitleDate
exploit-dbAuerswald COMpact 8.0B - Multiple Backdoors2021-12-06

References

→ the Explorer  ·  watch your stack  ·  NVD