CVE-2021-27446
CRITICAL
10.0
CVSS 3.1
Description
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (7)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Weintek | cMT-CTRL01 | — | unspecified < 20210302 |
| Weintek | cMT-FHD | — | unspecified < 20210208 |
| Weintek | cMT-G01/G02 | — | unspecified < 20210209 |
| Weintek | cMT-G03/G04 | — | unspecified < 20210222 |
| Weintek | cMT-HDM | — | unspecified < 20210204 |
| Weintek | cMT-SVR-1xx/2xx | — | unspecified < 20210305 |
| Weintek | cMT3071/cMT3072/cMT3090/cMT3103/cMT3151 | — | unspecified < 20210218 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-94 | cna | CWE-94: Code Injection |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (2)