CVE-2021-20122
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenticated with a super user account, or using a bypass authentication vulnerability like CVE-2021-20090 could leverage this issue to run commands or gain a shell as root on the target device.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.53% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- telus/prv65b444a-s-ts firmware
- Source
- vulnreport@tenable.com
References
- https://www.tenable.com/security/research/tra-2021-41Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-41Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.