High severity8.8NVD Advisory· Published Dec 31, 2025· Updated Jun 17, 2026
CVE-2021-47745
CVE-2021-47745
Description
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: =2.7.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.