VYPR
Unrated severityNVD Advisory· Published Jun 25, 2021· Updated Sep 17, 2024

WEIDMUELLER: WLAN devices affected by exploitable format string vulnerability

CVE-2021-33535

Description

In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A format string vulnerability in Weidmueller Industrial WLAN devices allows authenticated low-privilege users to execute remote code via a crafted time server entry.

Vulnerability

A format string vulnerability exists in the iw_console conio_writestr functionality of Weidmueller Industrial WLAN devices in multiple versions [1]. The vulnerability is triggered through a specially crafted time server entry that causes an overflow of the time server buffer. The affected product line and specific firmware versions are not enumerated in the available references [1].

Exploitation

An attacker must first authenticate as a low-privilege user to the device [1]. With that access, the attacker can send a specially crafted time server entry that exploits the format string flaw in the conio_writestr function [1]. The exploit does not require any additional user interaction or race condition windows.

Impact

Successful exploitation results in remote code execution on the target device [1]. The attacker gains arbitrary code execution at the privilege level of the affected process, which could lead to full compromise of the device's functionality and data confidentiality, integrity, and availability. The vendor advisory did not specify the degree of privilege escalation beyond the initial low-privilege user context [1].

Mitigation

The referenced advisory [1] does not provide a fixed version, release date, or workarounds for this vulnerability. Users are directed to contact the vendor for updated information. No known mitigation or patch has been disclosed as of the publication date. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog per the available information.

References
  1. Advisories

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Weidmüller/IE-WL(T)-BL-AP-CL-XXv5
    Range: IE-WL-BL-AP-CL-EU (2536600000)
  • Weidmüller/IE-WL(T)-VL-AP-CL-XXv5
    Range: IE-WL-VL-AP-BR-CL-EU (2536680000)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.