CVE-2021-43936 EXPLOIT
10.0
CRITICAL · CVSS 3.1 · EPSS 35.8% (pctl 98)
Patch early
A public exploit exists.
Description
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 35.8% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-12-06 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| webhmi | webhmi |
| webhmi | webhmi firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated) | 2021-12-13 |
References
→ the Explorer · watch your stack · NVD