Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-41314

EPSS 4.87% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-41314

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e.g., the "2" string). This leads to admin session crafting and therefore gaining full web UI admin privileges by an unauthenticated attacker. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TUP before 1.0.5.3, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS710TUP before 1.0.5.3, GS716TP before 1.0.4.2, GS716TPP before 1.0.4.2, GS724TPP before 2.0.6.3, GS724TPv2 before 2.0.6.3, GS728TPPv2 before 6.0.8.2, GS728TPv2 before 6.0.8.2, GS750E before 1.0.1.10, GS752TPP before 6.0.8.2, GS752TPv2 before 6.0.8.2, MS510TXM before 1.0.4.2, and MS510TXUP before 1.0.4.2.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
NETGEAR 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NETGEAR是美国网件(NETGEAR)公司的一款路由器。连接两个或多个网络的硬件设备,在网络间起网关的作用。 多种 NETGEAR 交换机存在注入漏洞,该漏洞源于产品Web UI中的密码字段未能正确处理用户输入数据。攻击者可通过该漏洞导致恶意文件创建以及权限提升。以下产品及版本受到影响: GC108P 1.0.8.2 之前版本、GC108PP 1.0.8.2 之前版本、GS108Tv3 7.0.7.2 之前版本、GS110TPP 7.0.7.2 之前版本、GS110TPv3 7.0.7.2 之前版本、
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2021-41314

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-41314

登录查看更多情报信息。

Same Patch Batch · n/a · 2021-09-16 · 31 CVEs total

CVE-2020-21531fig2dev 缓冲区错误漏洞
CVE-2020-21606Libde265 缓冲区错误漏洞
CVE-2020-21605Libde265 代码问题漏洞
CVE-2020-21604Libde265 缓冲区错误漏洞
CVE-2020-21603libde265缓冲区错误漏洞
CVE-2020-21602Libde265 缓冲区错误漏洞
CVE-2020-21601Libde265 缓冲区错误漏洞
CVE-2020-21600Libde265 缓冲区错误漏洞
CVE-2020-21599Libde265 缓冲区错误漏洞
CVE-2020-21598Libde265 缓冲区错误漏洞
CVE-2020-21597Libde265 缓冲区错误漏洞
CVE-2020-21596Libde265 缓冲区错误漏洞
CVE-2020-21595Libde265 缓冲区错误漏洞
CVE-2020-21594Libde265 缓冲区错误漏洞
CVE-2020-21532fig2dev 缓冲区错误漏洞
CVE-2020-21535Xfig fig2dev 缓冲区错误漏洞
CVE-2020-21529fig2dev 缓冲区错误漏洞
CVE-2021-40066Mobility 只读API 安全漏洞
CVE-2021-40067Mobility 安全漏洞
CVE-2020-14130Xiaomi community 安全漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-41314

No comments yet


Leave a comment