Scripting Syntax Vulnerability in Yamaha RTX830, NVR510, NVR700W, and RTX1210
CVE-2021-20844

5.7MEDIUM

Key Information:

Vendor
CVE Published:
24 November 2021

What is CVE-2021-20844?

A vulnerability in the Web GUI of several Yamaha devices allows remote authenticated attackers to exploit improper handling of HTTP request headers, potentially leading to the exposure of sensitive information. This issue primarily affects the RTX830, NVR510, NVR700W, and RTX1210 models if they are running specified versions or earlier. Exploitation would occur through specially crafted web pages, highlighting the necessity for timely updates and security practices.

Affected Version(s)

RTX830, NVR510, NVR700W, RTX1210 RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, RTX1210 Rev.14.01.38 and earlier

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.