Directory Traversal Vulnerability in Lantronix PremierWave 2050
CVE-2021-21896

4.9MEDIUM

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 December 2021

What is CVE-2021-21896?

A directory traversal issue has been identified in the Web Manager FsBrowseClean feature of Lantronix PremierWave 2050 version 8.9.0.0R4. This vulnerability allows an attacker to craft a specific HTTP request that can lead to the deletion of arbitrary files. By gaining authenticated access, the attacker can exploit this flaw, potentially compromising the integrity of the system's file structure.

Affected Version(s)

Lantronix Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.