9.8
CVSSv3

CVE-2021-29003

Published: 13/04/2021 Updated: 03/05/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote malicious users to execute arbitrary code via shell metacharacters to sys_config_valid.xgi, as demonstrated by the sys_config_valid.xgi?exeshell=%60telnetd%20%26%60 URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

genexis platinum 4410 firmware p4410-v2-1.28

Vendor Advisories

Check Point Reference: CPAI-2021-2113 Date Published: 28 Feb 2024 Severity: Critical ...

Exploits

Genexis PLATINUM 4410 version 21 P4410-V2-128 suffers from a remote command execution vulnerability ...

Github Repositories

CVE-2021-29003 hackerworldhomeblog/2021/03/19/rce-in-genexis-router/ Exploit db wwwexploit-dbcom/exploits/49764 medium sharmajijvsmediumcom/how-i-got-my-first-cve-af2c3009e409 Unit 42 palo alto networks unit42paloaltonetworkscom/network-attack-trends-february-april-2021/#:~:text=CVE%2D2021%2D29003,and%20achieve%20arbitrary%20command%20exe