CVE-2021-45876
Last modified
CVE-2021-45876 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Garo | Wallbox Gtb Firmware | <= 185 |
| Garo | Wallbox Gtc Firmware | <= 185 |
| Garo | Wallbox Glb Firmware | <= 185 |
References
- https://github.com/delikely/advisory/tree/main/GAROThird Party Advisory
- https://github.com/delikely/advisory/tree/main/GAROThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-45876?
How severe is CVE-2021-45876?
How do I fix CVE-2021-45876?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-45861There is an Assertion `num <= INT_BIT' failed at BitStreamRe…5.5
- CVE-2021-45863tsMuxer git-2678966 was discovered to contain a heap-based b…5.5
- CVE-2021-45864tsMuxer git-c6a0277 was discovered to contain a segmentation…5.5
- CVE-2021-45865A File Upload vulnerability exists in Sourcecodester Student…9.8
- CVE-2021-45866A Stored Cross Site Scripting (XSS) vulnerability exists in …5.4
- CVE-2021-45868In the Linux kernel before 5.15.3, fs/quota/quota_tree.c doe…5.5
- CVE-2021-45877Multiple versions of GARO Wallbox GLB/GTB/GTC are affected b…9.8
- CVE-2021-45878Multiple versions of GARO Wallbox GLB/GTB/GTC are affected b…9.1
- CVE-2021-45884In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNA…7.5
- CVE-2021-45885An issue was discovered in Stormshield Network Security (SNS…7.5
- CVE-2021-45886An issue was discovered in PONTON X/P Messenger before 3.11.…8.8
- CVE-2021-45887An issue was discovered in PONTON X/P Messenger before 3.11.…9.8
Are you affected by CVE-2021-45876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
