HIGH · 8.8

CVE-2021-39291

Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB...

Vulnerability Description

Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NetmoduleNetmodule Router Software< 4.3.0.113
NetmoduleNb1600-
NetmoduleNb1601-
NetmoduleNb1800-
NetmoduleNb1810-
NetmoduleNb2700-
NetmoduleNb2710-
NetmoduleNb2800-
NetmoduleNb2810-
NetmoduleNb3700-
NetmoduleNb3701-
NetmoduleNb3710-
NetmoduleNb3711-
NetmoduleNb3720-
NetmoduleNb3800-
NetmoduleNb800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-39291?

CVE-2021-39291 is a vulnerability with a CVSS score of 8.8 (HIGH). Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB...

How severe is CVE-2021-39291?

CVE-2021-39291 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-39291?

Check the references section above for vendor advisories and patch information. Affected products include: Netmodule Netmodule Router Software, Netmodule Nb1600, Netmodule Nb1601, Netmodule Nb1800, Netmodule Nb1810.