CVE-2021-40858
13.12.2021, 04:15
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.
Vendor | Product | Version |
---|---|---|
auerswald | compact_5500r_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | compact_5200r_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | compact_5000r_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | compact_4000_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | commander_6000r_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | commander_6000rx_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | commander_business\(19\"\)_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | commander_basic.2\(19\"\)_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | compact_5010_voip_ip_firmware | 𝑥 ≤ 8.0b |
auerswald | compact_5020_voip_ip_firmware | 𝑥 ≤ 8.0b |
𝑥
= Vulnerable software versions
References