Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Korenix
Subscribe
|
Jetwave 2212g
Subscribe
Jetwave 2212g Firmware
Subscribe
Jetwave 2212s
Subscribe
Jetwave 2212s Firmware
Subscribe
Jetwave 2212x
Subscribe
Jetwave 2212x Firmware
Subscribe
Jetwave 2311
Subscribe
Jetwave 2311 Firmware
Subscribe
Jetwave 3220
Subscribe
Jetwave 3220 Firmware
Subscribe
Jetwave 3420
Subscribe
Jetwave 3420 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25642 | Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:06:40.987Z
Reserved: 2021-08-18T00:00:00
Link: CVE-2021-39280
No data.
Status : Modified
Published: 2022-02-06T21:15:07.837
Modified: 2024-11-21T06:19:06.593
Link: CVE-2021-39280
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD