Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-21881 PoC — Lantronix PremierWave 2050 操作系统命令注入漏洞

Source
Associated Vulnerability
Title:Lantronix PremierWave 2050 操作系统命令注入漏洞 (CVE-2021-21881)
Description:Lantronix PremierWave 2050是美国Lantronix公司的一个嵌入式企业 Wi-Fi 模块。用于提供可靠且始终在线的 5G Wi-Fi 连接。 Lantronix PremierWave 2050 8.9.0.0R4版本存在操作系统命令注入漏洞,攻击者可利用该漏洞发送特殊设计的HTTP请求进行任意命令执行。
Description
Lantronix PremierWave 2050 8.9.0.0R4 contains an OS command injection vulnerability. A specially-crafted HTTP request can lead to command in the Web Manager Wireless Network Scanner. An attacker can make an authenticated HTTP request to trigger this vulnerability.
File Snapshot

id: CVE-2021-21881 info: name: Lantronix PremierWave 2050 8.9.0.0R4 - Remote Command Injection ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.