← Back to browse · API

CVE-2021-27132

Severity
CRITICAL
CVSS
9.8
EPSS
0.16062
Risk score
44.82
CISA KEV
No
PoC
No
Published
2021-02-27
Modified
2026-07-09
First seen
2026-08-05
Aliases
EUVD-2021-13899, GHSA-24PC-7PXR-JG3Q
Products
n/a:n/a n/a, sercomm:agcombo_vd625, sercomm:agcombo_vd625_firmware
Sources
nvd CVE-2021-27132
euvd EUVD-2021-13899

Description

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.

References