CRITICAL · 9.8

CVE-2021-26747

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

Vulnerability Description

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Netis-SystemsWf2780 Firmware2.3.40404
Netis-SystemsWf2780-
Netis-SystemsWf2411 Firmware1.1.29629
Netis-SystemsWf2411-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-26747?

CVE-2021-26747 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

How severe is CVE-2021-26747?

CVE-2021-26747 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-26747?

Check the references section above for vendor advisories and patch information. Affected products include: Netis-Systems Wf2780 Firmware, Netis-Systems Wf2780, Netis-Systems Wf2411 Firmware, Netis-Systems Wf2411.