{"api_version":"1","generated_at":"2026-07-24T23:23:13+00:00","cve":"CVE-2021-26606","urls":{"html":"https://cve.report/CVE-2021-26606","api":"https://cve.report/api/cve/CVE-2021-26606.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-26606","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-26606"},"summary":{"title":"CVE-2021-26606","description":"A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2021-08-06 15:15:00","updated_at":"2021-08-13 14:09:00"},"problem_types":["CWE-20","CWE-120"],"metrics":[],"references":[{"url":"https://boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36174","name":"https://boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36174","refsource":"MISC","tags":[],"title":"KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-26606","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-26606","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Thanks to Yoonho Kim for reporting this vulnerability.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"26606","vulnerable":"1","versionEndIncluding":"1.0.0.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dreamsecurity","cpe5":"magicline4nx.exe","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"26606","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","DATE_PUBLIC":"2021-08-06T01:26:00.000Z","ID":"CVE-2021-26606","STATE":"PUBLIC","TITLE":"DreamSecurity MagicLine Buffer Overflow Vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"MagicLine4NX.exe","version":{"version_data":[{"platform":"Windows","version_affected":"<","version_name":"1.0.0.17","version_value":"1.0.0.18"}]}}]},"vendor_name":"Dream Security Co.,Ltd"}]}},"credit":[{"lang":"eng","value":"Thanks to Yoonho Kim for reporting this vulnerability."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation"}]},{"description":[{"lang":"eng","value":"CWE-120 Buffer Overflow"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36174","name":"https://boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36174"}]},"solution":[{"lang":"eng","value":"Update software over 1.0.0.18 version or higher."}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-08-06 15:15:00","lastModifiedDate":"2021-08-13 14:09:00","problem_types":["CWE-20","CWE-120"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:dreamsecurity:magicline4nx.exe:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0.17","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"26606","Ordinal":"201677","Title":"CVE-2021-26606","CVE":"CVE-2021-26606","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"26606","Ordinal":"1","NoteData":"A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability is due to insufficient validation of the authorization certificate. An attacker could exploit this vulnerability by sending a crafted HTTP request an affected program. A successful exploit could allow the attacker to remotely execute arbitrary code on a target system.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"26606","Ordinal":"2","NoteData":"2021-08-06","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"26606","Ordinal":"3","NoteData":"2021-08-06","Type":"Other","Title":"Modified"}]}}}