Vulnerability Description
applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwrt | Openwrt | 19.07.0 |
Related Weaknesses (CWE)
References
- https://github.com/openwrt/luci/commit/9df7ea4d66644df69fcea18b36bc465912ffcPatchThird Party Advisory
- https://openwrt.org/advisory/2021-08-01-3PatchVendor Advisory
- https://github.com/openwrt/luci/commit/9df7ea4d66644df69fcea18b36bc465912ffcPatchThird Party Advisory
- https://openwrt.org/advisory/2021-08-01-3PatchVendor Advisory
FAQ
What is CVE-2021-28961?
CVE-2021-28961 is a vulnerability with a CVSS score of 8.8 (HIGH). applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.
How severe is CVE-2021-28961?
CVE-2021-28961 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28961?
Check the references section above for vendor advisories and patch information. Affected products include: Openwrt Openwrt.