MEDIUM · 4.0

CVE-2021-20121

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary f...

Vulnerability Description

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a specially prepared USB drive to the device, and making a series of crafted requests to the device's web interface.

CVSS Score

4.0

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
TelusPrv65B444A-S-Ts Firmware3.00.20
TelusPrv65B444A-S-Ts-

References

FAQ

What is CVE-2021-20121?

CVE-2021-20121 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary f...

How severe is CVE-2021-20121?

CVE-2021-20121 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20121?

Check the references section above for vendor advisories and patch information. Affected products include: Telus Prv65B444A-S-Ts Firmware, Telus Prv65B444A-S-Ts.