CVE-2021-39245
Last modified
CVE-2021-39245 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100 1.8.11.0, Nexto NX5101 1.8.11.0, Nexto NX5110 1.1.2.8, Nexto NX5210 1.1.2.8, Nexto Xpress XP300 1.8.11.0, Nexto Xpress XP315 1.8.11.0, Nexto Xpress XP325 1.8.11.0, Nexto Xpress XP340 1.8.11.0, and Hadron Xtorm HX3040 1.7.58.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Altus | Nexto Nx3003 Firmware | 1.8.11.0 |
| Altus | Nexto Nx3004 Firmware | 1.8.11.0 |
| Altus | Nexto Nx3005 Firmware | 1.8.11.0 |
| Altus | Nexto Nx3010 Firmware | 1.8.3.0 |
| Altus | Nexto Nx3020 Firmware | 1.8.3.0 |
| Altus | Nexto Nx3030 Firmware | 1.8.3.0 |
| Altus | Nexto Nx5100 Firmware | 1.8.11.0 |
| Altus | Nexto Nx5101 Firmware | 1.8.11.0 |
| Altus | Nexto Nx5110 Firmware | 1.1.2.8 |
| Altus | Nexto Nx5210 Firmware | 1.1.2.8 |
| Altus | Nexto Xpress Xp300 Firmware | 1.8.11.0 |
| Altus | Nexto Xpress Xp315 Firmware | 1.8.11.0 |
| Altus | Nexto Xpress Xp325 Firmware | 1.8.11.0 |
| Altus | Nexto Xpress Xp340 Firmware | 1.8.11.0 |
| Altus | Hadron Xtorm Hx3040 Firmware | 1.7.58.0 |
References
- https://seclists.org/fulldisclosure/2021/Aug/21Exploit, Mailing List, Third Party Advisory
- https://www.altus.com.br/Vendor Advisory
- https://seclists.org/fulldisclosure/2021/Aug/21Exploit, Mailing List, Third Party Advisory
- https://www.altus.com.br/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39245?
How severe is CVE-2021-39245?
How do I fix CVE-2021-39245?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-3924grav is vulnerable to Improper Limitation of a Pathname to a…7.5
- CVE-2021-39240An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 be…7.5
- CVE-2021-39241An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 be…5.3
- CVE-2021-39242An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 be…7.5
- CVE-2021-39243Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nex…6.5
- CVE-2021-39244Authenticated Semi-Blind Command Injection (via Parameter In…8.8
- CVE-2021-39246Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a …6.1
- CVE-2021-39247Zint Barcode Generator before 2.10.0 has a one-byte buffer o…6.5
- CVE-2021-39248Open edX through Lilac.1 allows XSS in common/static/common/…6.1
- CVE-2021-39249Invision Community (aka IPS Community Suite or IP-Board) bef…6.1
- CVE-2021-39250Invision Community (aka IPS Community Suite or IP-Board) bef…5.4
- CVE-2021-39251A crafted NTFS image can cause a NULL pointer dereference in…7.8
Are you affected by CVE-2021-39245?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
