CVE-2021-39280
06.02.2022, 21:15
Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.Enginsight
Vendor | Product | Version |
---|---|---|
korenix | jetwave_2212s_firmware | 𝑥 < 1.9.1 |
korenix | jetwave_2212g_firmware | 𝑥 < 1.8 |
korenix | jetwave_2311_firmware | 𝑥 ≤ 1.2 |
korenix | jetwave_3220_firmware | 𝑥 < 1.5.1 |
korenix | jetwave_3420_firmware | 𝑥 < 1.5.1 |
korenix | jetwave_2212x_firmware | 𝑥 < 1.9.1 |
𝑥
= Vulnerable software versions
References