CVE-2021-33533

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2021-026 Third Party Advisory
Configurations

Configuration 1


Information

Published : 2021-06-25 07:15

Updated : 2021-07-27 08:53


NVD link : CVE-2021-33533

Mitre link : CVE-2021-33533

Products Affected
No products.
CWE