Unrated severityNVD Advisory· Published Jan 15, 2022· Updated Aug 4, 2024
CVE-2021-33963
CVE-2021-33963
Description
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.
Affected products
2- China Mobile/An Lianbao WF-1description
- Range: = 1.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- iot.10086.cnmitrex_refsource_MISC
- github.com/pokerfacett/MY_CVE_CREDIT/blob/master/China%20Mobile%20An%20Lianbao%20WF-1%20router%20Command%20Injection9.mdmitrex_refsource_MISC
- www.cnvd.org.cn/flaw/show/CNVD-2021-03520mitrex_refsource_MISC
- www.ebuy7.com/item/china-mobile-wireless-router-qualcomm-qiki-wifi6-routing-mesh-network-home-5g-dual-frequency-double-gigabit-port-wall-wall-high-speed-%E2%80%8B%E2%80%8Bhigh-power-enhanced-dormitory-students-an-lianbao-wf-1-628692180620mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.