Improper Validation Vulnerability in NEC Aterm Routers
CVE-2021-20709
7.2HIGH
What is CVE-2021-20709?
A vulnerability present in the firmware of NEC Aterm routers allows an attacker with administrative privileges to execute arbitrary operating system commands. This vulnerability stems from improper validation of the integrity check value, which can be exploited by sending crafted requests to specific URLs. The affected products include WF1200CR, WG1200CR, and WG2600HS models with particular firmware versions. Maintaining updated firmware is essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
NEC Aterm devices Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier