CVE-2021-45876
Last modified
CVE-2021-45876 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Garo | Wallbox Gtb Firmware | <= 185 |
| Garo | Wallbox Gtc Firmware | <= 185 |
| Garo | Wallbox Glb Firmware | <= 185 |
References
- https://github.com/delikely/advisory/tree/main/GAROThird Party Advisory
- https://github.com/delikely/advisory/tree/main/GAROThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-45876?
How severe is CVE-2021-45876?
How do I fix CVE-2021-45876?
Are you affected by CVE-2021-45876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
