← Back to browse · API

CVE-2021-20991

Severity
CRITICAL
CVSS
9.8
EPSS
0.05437
Risk score
41.1
CISA KEV
No
PoC
No
Published
2021-04-19
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-8400, GHSA-2V74-GVXM-8WMQ
Products
Fibar Group S.A:Fibaro Home Center Home Center 2 ≤4.540, Fibar Group S.A:Fibaro Home Center Home Center Lite ≤4.540
Sources
euvd EUVD-2021-8400

Description

In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

References