← All CVEs

CVE-2021-42912

high · 8.8

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

8.8
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2021-12-16
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
fiberhomean5506-01-a_firmwarerp0509
fiberhomean5506-01-aall versions
fiberhomean5506-01-b_firmwarerp2610
fiberhomean5506-01-ball versions
fiberhomean5506-02-b_firmwarerp2520
fiberhomean5506-02-b_firmwarerp2521
fiberhomean5506-02-b_firmwarerp2603
fiberhomean5506-02-ball versions
fiberhomean5506-04-b_firmwarerp2510
fiberhomean5506-04-ball versions
fiberhomean5506-04-f_firmwarerp2617
fiberhomean5506-04-fall versions
fiberhomeaan5506-04-g2g_firmwarerp2560
fiberhomean5506-04-g2gall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-42912