CVE-2021-20844
Summary
| CVE | CVE-2021-20844 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-24 16:15:00 UTC |
| Updated | 2021-11-30 07:12:00 UTC |
| Description | Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ntt-west | Biz Box Nvr510 | - | All | All | All |
| Operating System | Ntt-west | Biz Box Nvr510 Firmware | All | All | All | All |
| Hardware | Ntt-west | Biz Box Nvr700w | - | All | All | All |
| Operating System | Ntt-west | Biz Box Nvr700w Firmware | All | All | All | All |
| Hardware | Ntt-west | Biz Box Rtx1210 | - | All | All | All |
| Operating System | Ntt-west | Biz Box Rtx1210 Firmware | All | All | All | All |
| Hardware | Ntt-west | Biz Box Rtx830 | - | All | All | All |
| Operating System | Ntt-west | Biz Box Rtx830 Firmware | All | All | All | All |
| Hardware | Yamaha | Nvr510 | - | All | All | All |
| Operating System | Yamaha | Nvr510 Firmware | All | All | All | All |
| Hardware | Yamaha | Nvr700w | - | All | All | All |
| Operating System | Yamaha | Nvr700w Firmware | All | All | All | All |
| Hardware | Yamaha | Rtx1210 | - | All | All | All |
| Operating System | Yamaha | Rtx1210 Firmware | All | All | All | All |
| Hardware | Yamaha | Rtx830 | - | All | All | All |
| Operating System | Yamaha | Rtx830 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 【NTT西日本】Biz Boxルータをご利用のお客さまへ - 法人・企業向けICTサービス | MISC | www.ntt-west.co.jp | |
| ヤマハルータをご利用のお客さまへ|お知らせ|法人のお客さま| NTT東日本 | MISC | business.ntt-east.co.jp | |
| FAQ for YAMAHA RT Series / Security | MISC | www.rtpro.yamaha.co.jp | |
| JVNVU#91161784: Multiple vulnerabilities in multiple Yamaha routers | MISC | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.