VYPR
Critical severity9.8NVD Advisory· Published Mar 6, 2022· Updated Jun 17, 2026

CVE-2021-46704

CVE-2021-46704

Description

In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
genieacsnpm
< 1.2.81.2.8

Affected products

3
  • Genieacs/Genieacs2 versions
    cpe:2.3:a:genieacs:genieacs:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:genieacs:genieacs:*:*:*:*:*:*:*:*range: >=1.2.0,<1.2.8
    • (no CPE)
  • ghsa-coords
    Range: < 1.2.8

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.