8.8

CVE-2021-20739

WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elecom ≫ Wrc-300febk Firmware
   Elecom ≫ Wrc-300febk Version -
Elecom ≫ Wrc-f300nf Firmware
   Elecom ≫ Wrc-f300nf Version -
Elecom ≫ Wrc-733febk Firmware
   Elecom ≫ Wrc-733febk Version -
Elecom ≫ Wrh-300rd Firmware
   Elecom ≫ Wrh-300rd Version -
Elecom ≫ Wrh-300bk Firmware
   Elecom ≫ Wrh-300bk Version -
Elecom ≫ Wrh-300sv Firmware
   Elecom ≫ Wrh-300sv Version -
Elecom ≫ Wrh-300wh Firmware
   Elecom ≫ Wrh-300wh Version -
Elecom ≫ Wrh-h300wh Firmware
   Elecom ≫ Wrh-h300wh Version -
Elecom ≫ Wrh-h300bk Firmware
   Elecom ≫ Wrh-h300bk Version -
Elecom ≫ Wrh-300bk-s Firmware
   Elecom ≫ Wrh-300bk-s Version -
Elecom ≫ Wrh-300wh-s Firmware
   Elecom ≫ Wrh-300wh-s Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://jvn.jp/en/vu/JVNVU94260088/index.html
Third Party Advisory
https://www.elecom.co.jp/news/security/20210706-01/
Vendor Advisory