Lantronix
Lantronix Premierwave 2050 Firmware: vulnerabilidades y CVE
Lantronix Premierwave 2050 Firmware tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-21896 | Media (6.5) | 2.2% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file deletion. An… |
| CVE-2021-21895 | Alta (7.2) | 2.3% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can… |
| CVE-2021-21894 | Crítica (9.1) | 2.4% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file overwrite FsTFtp file… |
| CVE-2021-21892 | Crítica (9.9) | 30% | — | 22 dic 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An… |
| CVE-2021-21891 | Crítica (9.1) | 3.0% | — | 22 dic 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in… |
| CVE-2021-21890 | Crítica (9.1) | 3.0% | — | 22 dic 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in… |
| CVE-2021-21889 | Crítica (9.9) | 2.8% | — | 22 dic 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker… |
| CVE-2021-21888 | Crítica (9.1) | 3.9% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command… |
| CVE-2021-21887 | Crítica (9.1) | 3.0% | — | 22 dic 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution.… |
| CVE-2021-21886 | Media (4.3) | 1.9% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make… |
| CVE-2021-21885 | Alta (7.2) | 2.4% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an… |
| CVE-2021-21884 | Crítica (9.1) | 5.3% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker… |
| CVE-2021-21883 | Crítica (9.9) | 6.1% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An… |
| CVE-2021-21882 | Alta (8.8) | 6.1% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can… |
| CVE-2021-21881 | Crítica (9.9) | 36% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker… |
| CVE-2021-21880 | Alta (7.2) | 2.4% | — | 22 dic 2021 | A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an… |
| CVE-2021-21878 | Media (4.9) | 1.2% | — | 22 dic 2021 | A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file… |
| CVE-2021-21877 | Crítica (9.1) | 2.7% | — | 22 dic 2021 | Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
| CVE-2021-21876 | Crítica (9.1) | 2.7% | — | 22 dic 2021 | Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
| CVE-2021-21875 | Crítica (9.1) | 2.9% | — | 22 dic 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2021-21874 | Crítica (9.1) | 2.9% | — | 22 dic 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2021-21873 | Crítica (9.1) | 2.9% | — | 22 dic 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2021-21872 | Crítica (9.9) | 6.1% | — | 22 dic 2021 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An… |