peter bassill · operator
$ cve CVE-2021-42165 JSON

CVE-2021-42165 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 14.1% (pctl 96)

Patch early

A public exploit exists.

Description

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.1% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2022-05-03
Last modified2026-06-17

Affected (2)

VendorProduct
mitrastargpt-2541gnac-n1
mitrastargpt-2541gnac-n1 firmware

Public exploits

SourceTitleDate
exploit-dbMitrastar GPT-2541GNAC-N1 - Privilege escalation2021-09-29

References

→ the Explorer  ·  watch your stack  ·  NVD