9.8
CVSSv3

CVE-2021-45876

Published: 21/03/2022 Updated: 28/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

garo wallbox_gtb_firmware

garo wallbox_gtc_firmware

garo wallbox_glb_firmware