Files
CVEs-PoC/2021/CVE-2021-20141.md
T
2024-06-09 00:33:16 +00:00

909 B

CVE-2021-20141

Description

An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

POC

Reference

Github

No PoCs found on GitHub currently.