Lantronix Premierwave 2050 Firmware vulnerabilities
23 known vulnerabilities affecting lantronix/premierwave_2050_firmware.
Total CVEs
23
CISA KEV
0
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH4MEDIUM3
Vulnerabilities
Page 1 of 2
CVE-2021-21881P1CRITICALCVSS 9.9ExploitedPoCv8.9.0.02021-12-22
CVE-2021-21881 [CRITICAL] CWE-78 CVE-2021-21881: An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionali
An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21872P1CRITICALCVSS 9.9Exploitedv8.9.0.02021-12-22
CVE-2021-21872 [CRITICAL] CWE-78 CVE-2021-21872: An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionalit
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21892P2CRITICALCVSS 9.9v8.9.0.02021-12-22
CVE-2021-21892 [CRITICAL] CWE-121 CVE-2021-21892: A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lan
A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21883P2CRITICALCVSS 9.9v8.9.0.02021-12-22
CVE-2021-21883 [CRITICAL] CWE-78 CVE-2021-21883: An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of L
An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21889P2CRITICALCVSS 9.9v8.9.0.02021-12-22
CVE-2021-21889 [CRITICAL] CWE-121 CVE-2021-21889: A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantroni
A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21882P2HIGHCVSS 8.8v8.9.0.02021-12-22
CVE-2021-21882 [HIGH] CWE-78 CVE-2021-21882: An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix
An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21884P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21884 [CRITICAL] CWE-78 CVE-2021-21884: An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lant
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21888P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21888 [CRITICAL] CWE-78 CVE-2021-21888: An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality
An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21873P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21873 [CRITICAL] CWE-78 CVE-2021-21873: A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter.
A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21875P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21875 [CRITICAL] CWE-78 CVE-2021-21875: A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter.
A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21874P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21874 [CRITICAL] CWE-78 CVE-2021-21874: A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter.
A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21891P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21891 [CRITICAL] CWE-121 CVE-2021-21891: A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of
A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletefile). An attacker can make an authenticated HTTP request to trigger this vulnerabilit
nvd
CVE-2021-21890P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21890 [CRITICAL] CWE-121 CVE-2021-21890: A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of
A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution in the vulnerable portion of the branch (deletedir). An attacker can make an authenticated HTTP request to trigger this vulnerability
nvd
CVE-2021-21887P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21887 [CRITICAL] CWE-121 CVE-2021-21887: A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality o
A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21876P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21876 [CRITICAL] CWE-78 CVE-2021-21876: Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker
Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.
nvd
CVE-2021-21877P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21877 [CRITICAL] CWE-78 CVE-2021-21877: Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attack
Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.
nvd
CVE-2021-21894P3CRITICALCVSS 9.1v8.9.0.02021-12-22
CVE-2021-21894 [CRITICAL] CWE-22 CVE-2021-21894: A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix Prem
A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file overwrite FsTFtp file disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21895P3HIGHCVSS 7.2v8.9.0.02021-12-22
CVE-2021-21895 [HIGH] CWE-22 CVE-2021-21895: A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix Prem
A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21880P3HIGHCVSS 7.2v8.9.0.02021-12-22
CVE-2021-21880 [HIGH] CWE-22 CVE-2021-21880: A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix
A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
CVE-2021-21885P3HIGHCVSS 7.2v8.9.0.02021-12-22
CVE-2021-21885 [HIGH] CWE-22 CVE-2021-21885: A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix Prem
A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.
nvd
1 / 2Next →