VulnerabilityModified
CVE-2021-42912
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability.
HIGH 8.8EPSS 10.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.09% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- fiberhome/an5506-01-a firmware · fiberhome/an5506-01-b firmware · fiberhome/an5506-02-b firmware · fiberhome/an5506-04-b firmware · fiberhome/an5506-04-f firmware · fiberhome/aan5506-04-g2g firmware
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.