Weintek EasyWeb cMT Code Injection
CVE-2021-27446
10CRITICAL
What is CVE-2021-27446?
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
Affected Version(s)
cMT-CTRL01 < 20210302
cMT-FHD < 20210208
cMT-G01/G02 < 20210209
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcin Dudek from CERT.PL reported these vulnerabilities to CISA.
