CVE-2021-22909
27.05.2021, 12:15
A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-middle (MitM) attack during a firmware update. This vulnerability is fixed in EdgeMAX EdgeRouter V2.0.9-hotfix.1 and later.Enginsight
Vendor | Product | Version |
---|---|---|
ui | edgemax_edgerouter_firmware | 𝑥 ≤ 2.0.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-300 - Channel Accessible by Non-EndpointThe product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
- CWE-295 - Improper Certificate ValidationThe software does not validate, or incorrectly validates, a certificate.