CVE-2021-35402 PUBLISHED

Assigner: mitre
Reserved: 23.06.2021 Published: 20.02.2026 Updated: 20.02.2026

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 10

Product Status

Vendor PROLiNK
Product PRC2402M
Versions Default: unknown
  • affected from 20190909 to 2021-06-13 (excl.)

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE