CVE Feed

    Dashboard / CVE / CVE-2020-21992

    CVE-2020-21992

    Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail' module through web.cgi binary. The vulnerable CGI binary (ELF 32-bit LSB executable, ARM) is calling the 'sh' executable via the system() function to issue a command using the mailx service and its vulnerable string format parameter allowing for OS command injection with root privileges. An attacker can remotely execute system commands as the root user using default credentials and bypass access controls in place.

    Published:Apr 29, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 29, 2021
    EPSS Score:0.04453
    CVSS Score:8.8

    Affected Products

    Vendor
    Inim
    Product
    Smartliving 10100l
    Vendor
    Inim
    Product
    Smartliving 10100l Firmware
    Vendor
    Inim
    Product
    Smartliving 10100lg3
    Vendor
    Inim
    Product
    Smartliving 10100lg3 Firmware
    Vendor
    Inim
    Product
    Smartliving 1050
    Vendor
    Inim
    Product
    Smartliving 1050 Firmware
    Vendor
    Inim
    Product
    Smartliving 1050g3
    Vendor
    Inim
    Product
    Smartliving 1050g3 Firmware
    Vendor
    Inim
    Product
    Smartliving 505
    Vendor
    Inim
    Product
    Smartliving 505 Firmware
    Vendor
    Inim
    Product
    Smartliving 515
    Vendor
    Inim
    Product
    Smartliving 515 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High