VulnerabilityModified
CVE-2021-38306
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
CRITICAL 9.8EPSS 8.96%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.96% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- lg/n1t1 firmware
- Source
- cve@mitre.org
References
- https://www.lg.com/uk/support/product/lg-N1T1DD1Product, Vendor Advisory
- https://www.lg.com/us/burners-drives/lg-N1T1-network-attached-storageProduct, Vendor Advisory
- https://zerosecuritypenetrationtesting.com/?page_id=306Exploit, Third Party Advisory, URL Repurposed
- https://www.lg.com/uk/support/product/lg-N1T1DD1Product, Vendor Advisory
- https://www.lg.com/us/burners-drives/lg-N1T1-network-attached-storageProduct, Vendor Advisory
- https://zerosecuritypenetrationtesting.com/?page_id=306Exploit, Third Party Advisory, URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.