CVE-2021-46422
Description
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
In plain language
AI Act nowIf you use Telesquare SDT-CW3B1 firmware 1.1.0, a remote attacker can run system commands on your device over the network without logging in—this is a high-risk issue if your device is reachable.
CVE-2021-46422 is an OS command injection in Telesquare SDT-CW3B1 firmware 1.1.0 that enables unauthenticated remote attackers to execute arbitrary operating system commands via the device’s network-facing web interface input.
What to do now
- Check whether your Telesquare SDT-CW3B1 is running firmware version 1.1.0.
- Confirm whether the device’s network interface/web access is reachable from the internet (not just inside your office).
- If it is reachable and you can’t upgrade, immediately restrict access at your firewall/router so it is not reachable from the internet.
- Contact your vendor/IT support and ask for the fixed firmware for CVE-2021-46422; deploy it as soon as it is provided (no patch is currently documented in the findings).
- Monitor for signs of botnet activity (suspicious outbound connections, unexpected reboots, changes to device behavior).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-46422 and every CVE in our database. Create a free account — no credit card required.
Create Free Account