Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20140

Опубликовано: 09 дек. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 8.3
EPSS Низкий

Описание

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:*
Версия до 04.0004.12 (включая)
cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.07766
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
больше 3 лет назад

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

EPSS

Процентиль: 92%
0.07766
Низкий

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-78