.. / CVE-2021-46422

Exploit for SDT-CW3B1 1.1.0 - OS Command Injection (CVE-2021-46422)

Description:

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

Nuclei Template

View the template here CVE-2021-46422.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-46422.yaml
Copy

References:

http://packetstormsecurity.com/files/167201/SDT-CW3B1-1.1.0-Command-Injection.html
https://www.exploit-db.com/exploits/50936
https://drive.google.com/drive/folders/1YJlVlb4SlTEGONzIjiMwd2P7ucP_Pm7T?usp=sharing
https://drive.google.com/drive/folders/1YJlVlb4SlTEGONzIjiMwd2P7ucP_Pm7T?
https://nvd.nist.gov/vuln/detail/CVE-2021-46422