CVE-2021-33534

moderate-risk
Published 2021-06-25

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.

Do I need to act?

~
3.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10 High
NETWORK / LOW complexity

Affected Products (8)

Ie-Wl-Bl-Ap-Cl-Eu Firmware
Ie-Wlt-Bl-Ap-Cl-Eu Firmware
Ie-Wl-Bl-Ap-Cl-Us Firmware
Ie-Wlt-Bl-Ap-Cl-Us Firmware
Ie-Wl-Vl-Ap-Br-Cl-Eu Firmware
Ie-Wlt-Vl-Ap-Br-Cl-Eu Firmware
Ie-Wl-Vl-Ap-Br-Cl-Us Firmware
Ie-Wlt-Vl-Ap-Br-Cl-Us Firmware

Affected Vendors

47
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 7/34 · Low
Exposure 14/34 · Moderate