CVE-2021-21917
Description
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated SQL injection in Advantech R-SeeNet 2.4.15 via the 'ord' parameter on the group_list page allows unauthenticated read access via CSRF.
Vulnerability
An exploitable SQL injection vulnerability exists in the group_list page of Advantech R-SeeNet version 2.4.15 (30.07.2021) [1]. The vulnerability is triggered via a specially-crafted HTTP request targeting the ord parameter [1]. The root cause is the misuse of prepared statements combined with SQL concatenation in stored procedures; variables that are initially sanitized lose that protection when the final prepared statement is executed from a dynamic SQL variable without parameter bindings [1].
Exploitation
An attacker can exploit this vulnerability by sending an authenticated HTTP request with a malicious ord parameter to the group_list page [1]. The attacker can make these requests as any authenticated user, or can leverage cross-site request forgery (CSRF) to trick a legitimate user into performing the request [1]. No special privileges beyond a valid session are required.
Impact
Successful exploitation allows the attacker to execute arbitrary SQL queries against the backend database, leading to unauthorized read access to sensitive data [1]. According to the CVSS vector (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), this can result in high confidentiality impact with no impact on integrity or availability, and the scope is changed [1].
Mitigation
At the time of disclosure (2021-12-22), no official patch or fixed version was available [1]. Users should monitor the vendor's advisory page for updates, restrict network access to the R-SeeNet web interface, and implement CSRF protections such as anti-CSRF tokens [1]. If no fix is released, consider upgrading to a supported version or replacing the product.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Advantech/R-SeeNetdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2021-1363mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.