Vulnerability Details CVE-2021-21881
An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.927
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 9.0
Products affected by CVE-2021-21881
-
cpe:2.3:h:lantronix:premierwave_2050:-
-
cpe:2.3:o:lantronix:premierwave_2050_firmware:8.9.0.0