CVE Feed

    Dashboard / CVE / CVE-2021-20122

    CVE-2021-20122

    The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenticated with a super user account, or using a bypass authentication vulnerability like CVE-2021-20090 could leverage this issue to run commands or gain a shell as root on the target device.

    Published:Oct 11, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 11, 2021
    EPSS Score:0.09395
    CVSS Score:7.2

    Affected Products

    Vendor
    Telus
    Product
    Prv65b444a-s-ts
    Vendor
    Telus
    Product
    Prv65b444a-s-ts Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High