HIGH · 8.8

CVE-2021-42912

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root...

Vulnerability Description

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FiberhomeAn5506-01-A Firmwarerp0509
FiberhomeAn5506-01-A-
FiberhomeAn5506-01-B Firmwarerp2610
FiberhomeAn5506-01-B-
FiberhomeAn5506-02-B Firmwarerp2520
FiberhomeAn5506-02-B-
FiberhomeAn5506-04-B Firmwarerp2510
FiberhomeAn5506-04-B-
FiberhomeAn5506-04-F Firmwarerp2617
FiberhomeAn5506-04-F-
FiberhomeAan5506-04-G2G Firmwarerp2560
FiberhomeAn5506-04-G2G-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-42912?

CVE-2021-42912 is a vulnerability with a CVSS score of 8.8 (HIGH). FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root...

How severe is CVE-2021-42912?

CVE-2021-42912 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-42912?

Check the references section above for vendor advisories and patch information. Affected products include: Fiberhome An5506-01-A Firmware, Fiberhome An5506-01-A, Fiberhome An5506-01-B Firmware, Fiberhome An5506-01-B, Fiberhome An5506-02-B Firmware.