CVE-2021-33537
Estado: ModificadaAlta (8.8)—
In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.61%
- Percentil entre todas las CVEs puntuadas: 75
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
Weidmueller — Ie-wl-bl-ap-cl-eu FirmwareWeidmueller — Ie-wl-bl-ap-cl-us FirmwareWeidmueller — Ie-wl-vl-ap-br-cl-eu FirmwareWeidmueller — Ie-wl-vl-ap-br-cl-us FirmwareWeidmueller — Ie-wlt-bl-ap-cl-eu FirmwareWeidmueller — Ie-wlt-bl-ap-cl-us FirmwareWeidmueller — Ie-wlt-vl-ap-br-cl-eu FirmwareWeidmueller — Ie-wlt-vl-ap-br-cl-us Firmware
CWE
- CWE-120
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-33537",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Weidmüller",
"product": "IE-WL(T)-BL-AP-CL-XX",
"versions": [
{
"status": "affected",
"version": "IE-WL-BL-AP-CL-EU (2536600000)",
"versionType": "custom",
"lessThanOrEqual": "V1.16.18 (Build 18081617)"
},
{
"status": "affected",
"version": "IE-WLT-BL-AP-CL-EU (2536650000)",
"versionType": "custom",
"lessThanOrEqual": "V1.16.18 (Build 18081617)"
},
{
"status": "affected",
"version": "IE-WL-BL-AP-CL-US (2536660000)",
"versionType": "custom",
"lessThanOrEqual": "V1.16.18 (Build 18081617)"
},
{
"status": "affected",
"version": "IE-WLT-BL-AP-CL-US (2536670000)",
"versionType": "custom",
"lessThanOrEqual": "V1.16.18 (Build 18081617)"
}
]
},
{
"vendor": "Weidmüller",
"product": "IE-WL(T)-VL-AP-CL-XX",
"versions": [
{
"status": "affected",
"version": "IE-WL-VL-AP-BR-CL-EU (2536680000)",
"versionType": "custom",
"lessThanOrEqual": "V1.11.10 (Build 18122616)"
},
{
"status": "affected",
"version": "IE-WLT-VL-AP-BR-CL-EU (2536690000)",
"versionType": "custom",
"lessThanOrEqual": "V1.11.10 (Build 18122616)"
},
{
"status": "affected",
"version": "IE-WL-VL-AP-BR-CL-US (2536700000)",
"versionType": "custom",
"lessThanOrEqual": "V1.11.10 (Build 18122616)"
},
{
"status": "affected",
"version": "IE-WLT-VL-AP-BR-CL-US (2536710000)",
"versionType": "custom",
"lessThanOrEqual": "V1.11.10 (Build 18122616)"
}
]
}
]
}
],
"published": "2021-06-25T19:15:09.503",
"references": [
{
"url": "https://cert.vde.com/en-us/advisories/vde-2021-026",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/en-us/advisories/vde-2021-026",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability."
},
{
"lang": "es",
"value": "En los dispositivos Weidmueller Industrial WLAN en múltiples versiones, se presenta una vulnerabilidad de ejecución de código remota explotable en la funcionalidad configuration parsing iw_webs. Una entrada de nombre de usuario especialmente diseñada puede causar un desbordamiento de búfer de mensaje de error, resultando en una ejecución de código remota. Un atacante puede enviar comandos mientras está autenticado como un usuario poco privilegiado para desencadenar esta vulnerabilidad"
}
],
"lastModified": "2026-06-17T03:54:44.780",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E409B45-BF28-41AD-B3A7-656FBAF9597D",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-bl-ap-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "26A4612B-2370-42CA-8EC4-5C74382ABDA6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17F26A4C-FDBA-48A8-AC05-1A779F0051F3",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-bl-ap-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FC895FDA-C846-4885-AADB-DED6EC868C3B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C589467-C35D-43E8-AE06-9C0541DF2190",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-bl-ap-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97D7BBC3-6F43-47B5-81E2-431C8837BB3A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E1B5E87-7D1E-45FD-894C-31167B80BEB1",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-bl-ap-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6D38EC42-5C2E-4ACE-88A1-2890632E51DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C2C095A-F606-4A7A-9836-EAA17A648E50",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-vl-ap-br-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "17790AD1-5DE3-47F4-A16C-67C7DFE56128"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE71A6A8-3E2A-4EC3-A719-0AC48B99C1F5",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-vl-ap-br-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "23E4AE7D-CA1F-45FC-9D8F-725E71832D2A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C171799A-4FEE-43F4-A7EE-8B1A52828FF7",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-vl-ap-br-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2DED5CF2-3B42-4D92-9647-AC54D07C6B20"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF79779D-863D-4B8B-A4B4-BFD0F3528442",
"versionEndIncluding": "1.16.18"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-vl-ap-br-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1209D9A9-D6AA-44C3-AD34-18C145851D5B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6210516-CB15-4099-B91E-63AE16C71B17",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-bl-ap-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "26A4612B-2370-42CA-8EC4-5C74382ABDA6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA154861-7D17-4FF1-8326-6B01B1E4A624",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-bl-ap-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FC895FDA-C846-4885-AADB-DED6EC868C3B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E865089B-638A-491A-9527-EB1A21C9A3D9",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-bl-ap-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97D7BBC3-6F43-47B5-81E2-431C8837BB3A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-bl-ap-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A3DCCA5-38A5-4661-8EA5-5DB21C92DA56",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-bl-ap-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6D38EC42-5C2E-4ACE-88A1-2890632E51DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B455D775-9B0E-4DCF-BDA6-0861F5C34362",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-vl-ap-br-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "17790AD1-5DE3-47F4-A16C-67C7DFE56128"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-eu_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE88298B-D13E-4B19-8C77-15FB57FC4A9A",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-vl-ap-br-cl-eu:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "23E4AE7D-CA1F-45FC-9D8F-725E71832D2A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wl-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D71C498-B58B-4FDC-AA9F-508D61F03E8B",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wl-vl-ap-br-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2DED5CF2-3B42-4D92-9647-AC54D07C6B20"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:weidmueller:ie-wlt-vl-ap-br-cl-us_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16DA2FEB-D762-44C1-9C45-3FC6017CE1D7",
"versionEndIncluding": "1.11.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:weidmueller:ie-wlt-vl-ap-br-cl-us:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1209D9A9-D6AA-44C3-AD34-18C145851D5B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}