CVE-2021-31574

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mediatek:en7580_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:en7580:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mediatek:en7528_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:en7528:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-20 CWE-77

Information

Published : 2023-02-06 22:15

Updated : 2024-02-28 19:51


NVD link : CVE-2021-31574

Mitre link : CVE-2021-31574

CVE.ORG link : CVE-2021-31574


JSON object : View

Products Affected

mediatek

  • en7528
  • en7580
  • en7580_firmware
  • en7528_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')