Description
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
Published: 2022-02-06
Score: 8.8 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-25642 Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
History

No history.

Subscriptions

Korenix Jetwave 2212g Jetwave 2212g Firmware Jetwave 2212s Jetwave 2212s Firmware Jetwave 2212x Jetwave 2212x Firmware Jetwave 2311 Jetwave 2311 Firmware Jetwave 3220 Jetwave 3220 Firmware Jetwave 3420 Jetwave 3420 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T02:06:40.987Z

Reserved: 2021-08-18T00:00:00.000Z

Link: CVE-2021-39280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-06T21:15:07.837

Modified: 2024-11-21T06:19:06.593

Link: CVE-2021-39280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses