peter bassill · operator
$ cve CVE-2021-43936 JSON

CVE-2021-43936 EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 35.8% (pctl 98)

Patch early

A public exploit exists.

Description

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS35.8% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2021-12-06
Last modified2026-06-17

Affected (2)

VendorProduct
webhmiwebhmi
webhmiwebhmi firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD