CVE-2021-27691
critical · 9.8Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.
9.8
CVSS
25.2%
EPSS (exploit prob.)
98th
EPSS percentile
2021-04-16
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tendacn | g0_firmware | 15.11.0.5(5876)_cn |
| tendacn | g0_firmware | 15.11.0.6(9039)_cn |
| tendacn | g0 | all versions |
| tendacn | g1_firmware | 15.11.0.16(9024)_cn |
| tendacn | g1_firmware | 15.11.0.17(9502)_cn |
| tendacn | g1 | all versions |
| tendacn | g3_firmware | 15.11.0.16(9024)_cn |
| tendacn | g3_firmware | 15.11.0.17(9502)_cn |
| tendacn | g3 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-27691