CVE-2021-46422
HIGH 10.0EPSS 94.3%
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 94.34% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-78
- Published
- 2022-04-27
- Updated
- 2024-08-04
Proof-of-concept exploits (14)
- http://packetstormsecurity.com/files/167387/Telesquare-SDT-CW3B1-1.1.0-Command-Injection.…
- https://drive.google.com/drive/folders/1YJlVlb4SlTEGONzIjiMwd2P7ucP_Pm7T?usp=sharing
- CJ-0107/cve-2021-464220★ · 2022-10-16
- CJ-0107/cve-2022-261341★ · 2022-10-16
- Chocapikk/CVE-2021-464222★ · 2022-10-16
- ZAxyr/CVE-2021-464220★ · 2022-10-16
- kailing0220/CVE-2021-464221★ · 2022-10-16
- kelemaoya/CVE-2021-464220★ · 2022-10-16
- latings/CVE-2021-464221★ · 2022-10-16
- nobodyatall648/CVE-2021-464221★ · 2022-05-24
- polerstar/CVE-2021-46422-poc1★ · 2022-10-16
- twoning/CVE-2021-46422_PoC0★ · 2022-07-14
- yigexioabai/CVE-2021-46422_RCE0★ · 2022-10-15
- yyqxi/CVE-2021-464222★ · 2022-10-16