Medium severity4.9NVD Advisory· Published Dec 13, 2021· Updated Jun 17, 2026
CVE-2021-40858
CVE-2021-40858
Description
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- cpe:2.3:o:auerswald:commander_6000r_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:commander_6000rx_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:commander_basic.2\(19\"\)_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:commander_business\(19\"\)_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_4000_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_5000r_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_5010_voip_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_5020_voip_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_5200r_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- cpe:2.3:o:auerswald:compact_5500r_ip_firmware:*:*:*:*:*:*:*:*Range: <=8.0b
- Auerswald/COMpact 5500Rdescription
- Range: <8.2B
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/165166/Auerswald-COMpact-8.0B-Arbitrary-File-Disclosure.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.redteam-pentesting.de/advisories/rt-sa-2021-006nvdExploitThird Party Advisory
- www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analysesnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.