CVE-2021-38703
Summary
| CVE | CVE-2021-38703 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-01 12:15:00 UTC |
| Updated | 2023-08-08 14:22:00 UTC |
| Description | Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise user input to the syslog configuration form. An authenticated remote attacker could leverage this to alter the device configuration and achieve remote code execution. This can be exploited in conjunction with CVE-2021-20090. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Kpn | Experia Wifi | - | All | All | All |
| Operating System | Kpn | Experia Wifi Firmware | 1.00.15 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Getting a root shell on an old KPN Experia Wifi (CVE-2021-38703) | Habbie's journal | MISC | 7bits.nl | |
| Experia WiFi - KPN Webshop | MISC | www.kpnwebshop.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.