CVE-2021-20121
Last modified
CVE-2021-20121 is a medium-severity vulnerability rated 4/10 on the CVSS scale. The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a specially prepared USB drive to the device, and making a series of crafted requests to the device's web interface.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a specially prepared USB drive to the device, and making a series of crafted requests to the device's web interface.
Metrics
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Telus | Prv65b444a-S-Ts Firmware | 3.00.20 |
References
- https://www.tenable.com/security/research/tra-2021-41Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-41Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20121?
How severe is CVE-2021-20121?
How do I fix CVE-2021-20121?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20116A reflected cross-site scripting vulnerability exists in TCE…6.1
- CVE-2021-20117Nessus Agent 8.3.0 and earlier was found to contain a local …6.7
- CVE-2021-20118Nessus Agent 8.3.0 and earlier was found to contain a local …6.7
- CVE-2021-20119The password change utility for the Arris SurfBoard SB8200 c…7.1
- CVE-2021-2012Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-20120The administration web interface for the Arris Surfboard SB8…8.8
- CVE-2021-20122The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version …7.2
- CVE-2021-20123A local file inclusion vulnerability exists in Draytek Vigor…7.5
- CVE-2021-20124A local file inclusion vulnerability exists in Draytek Vigor…7.5
- CVE-2021-20125An arbitrary file upload and directory traversal vulnerabili…9.8
- CVE-2021-20126Draytek VigorConnect 1.6.0-B3 lacks cross-site request forge…8.8
- CVE-2021-20127An arbitrary file deletion vulnerability exists in the file …8.1
Are you affected by CVE-2021-20121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
