Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.
                
            References
                    | Link | Resource | 
|---|---|
| http://packetstormsecurity.com/files/165875/Korenix-Technology-JetWave-CSRF-Command-Injection-Missing-Authentication.html | Third Party Advisory VDB Entry | 
| https://www.korenix.com/en/product/search.aspx?kw=JetWave | Product Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
Configuration 5 (hide)
| AND | 
            
            
 
  | 
    
Configuration 6 (hide)
| AND | 
            
            
 
  | 
    
History
                    No history.
Information
                Published : 2022-02-06 21:15
Updated : 2022-02-11 03:19
NVD link : CVE-2021-39280
Mitre link : CVE-2021-39280
CVE.ORG link : CVE-2021-39280
JSON object : View
Products Affected
                korenix
- jetwave_3420
 - jetwave_2212s
 - jetwave_3420_firmware
 - jetwave_2311
 - jetwave_2212g_firmware
 - jetwave_2212g
 - jetwave_2311_firmware
 - jetwave_2212x_firmware
 - jetwave_3220
 - jetwave_2212s_firmware
 - jetwave_3220_firmware
 - jetwave_2212x
 
CWE
                