VYPR
Unrated severityNVD Advisory· Published Oct 24, 2022· Updated May 7, 2025

spx_restservice FirstReset_handler_func Broken Access Control

CVE-2021-26733

Description

A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) condition. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated attacker can remotely trigger a DoS on Lanner IAC-AST2500A BMC via broken access control in the FirstReset_handler_func function.

Vulnerability

A broken access control vulnerability exists in the FirstReset_handler_func function of the spx_restservice component in Lanner Inc IAC-AST2500A standard firmware version 1.10.0. The flaw allows an attacker to send reboot commands to the BMC without proper authentication or authorization checks [1], [2].

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by sending crafted network requests to the BMC's REST service. No prior authentication or user interaction is required. The attacker targets the FirstReset_handler_func endpoint to issue reboot commands [1], [2].

Impact

Successful exploitation causes the BMC to reboot immediately, resulting in a Denial-of-Service (DoS) condition. The BMC becomes inaccessible to legitimate users until the reboot completes. This impacts the availability of the management interface and any dependent remote monitoring or management functions [1], [2].

Mitigation

Fixed firmware versions that address this vulnerability are available from Lanner technical support. Asset owners should contact Lanner to obtain the patched firmware and apply it to affected devices [1], [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.