{"api_version":"1","generated_at":"2026-07-23T19:01:57+00:00","cve":"CVE-2021-37911","urls":{"html":"https://cve.report/CVE-2021-37911","api":"https://cve.report/api/cve/CVE-2021-37911.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-37911","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-37911"},"summary":{"title":"CVE-2021-37911","description":"The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2021-08-30 15:15:00","updated_at":"2021-09-10 15:31:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-5047-7ef35-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5047-7ef35-1.html","refsource":"MISC","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心-BenQ EH600 - Improper Privilege Management","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-37911","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37911","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"BenQ","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"37911","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"benq","cpe5":"eh600","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"37911","vulnerable":"1","versionEndIncluding":"01.00.30.00","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"benq","cpe5":"eh600_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"TWCERT/CC","ASSIGNER":"cve@cert.org.tw","DATE_PUBLIC":"2021-08-30T14:21:00.000Z","ID":"CVE-2021-37911","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"EH600 OTA","version":{"version_data":[{"platform":"AOSP 6.0","version_affected":"<=","version_value":"v01.00.30.00"}]}}]},"vendor_name":"BenQ"}]}},"credit":[{"lang":"eng","value":"BenQ"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-269 Improper Privilege Management"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.twcert.org.tw/tw/cp-132-5047-7ef35-1.html","name":"https://www.twcert.org.tw/tw/cp-132-5047-7ef35-1.html"}]},"solution":[{"lang":"eng","value":"Update EH600 OTA to v01.00.30.00 (AOSP 6.0)"}],"source":{"advisory":"TVN-202108008","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-08-30 15:15:00","lastModifiedDate":"2021-09-10 15:31:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:C/I:C/A:C","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":8.3},"severity":"HIGH","exploitabilityScore":6.5,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:benq:eh600_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"01.00.30.00","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:benq:eh600:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"37911","Ordinal":"213508","Title":"CVE-2021-37911","CVE":"CVE-2021-37911","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"37911","Ordinal":"1","NoteData":"The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"37911","Ordinal":"2","NoteData":"2021-08-30","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"37911","Ordinal":"3","NoteData":"2021-08-30","Type":"Other","Title":"Modified"}]}}}