HIGH · 8.8

CVE-2021-20144

An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same ne...

Vulnerability Description

An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GryphonconnectGryphon Tower Firmware<= 04.0004.12
GryphonconnectGryphon Tower-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-20144?

CVE-2021-20144 is a vulnerability with a CVSS score of 8.8 (HIGH). An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same ne...

How severe is CVE-2021-20144?

CVE-2021-20144 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-20144?

Check the references section above for vendor advisories and patch information. Affected products include: Gryphonconnect Gryphon Tower Firmware, Gryphonconnect Gryphon Tower.