High severity7.8NVD Advisory· Published Feb 25, 2022· Updated Jun 17, 2026
CVE-2021-44132
CVE-2021-44132
Description
A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.
Affected products
3- cpe:2.3:o:c-data_onu4ferw_project:c-data_onu4ferw_firmware:*:*:*:*:*:*:*:*Range: <=2.1.13_x139
- C-DATA/ONU4FERWdescription
Patches
Vulnerability mechanics
References
2- exploitwriter.io/2022/02/25/os-command-injection-in-c-data-onu4ferw-cve-2021-44132/nvdExploitThird Party Advisory
- exploitwriter.wordpress.com/2021/11/19/remote-code-execution-in-c-data-onu4ferw/nvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.