← Back to browse · API

CVE-2021-31573

Severity
CRITICAL
CVSS
9.8
EPSS
0.01679
Risk score
39.79
CISA KEV
No
PoC
No
Published
2023-02-06
Modified
2025-03-26
First seen
2026-08-07
Aliases
EUVD-2021-18467, GHSA-WGXW-VJVF-VR8H
Products
MediaTek, Inc.:EN7528, EN7580 Linux SDK versions less than TLM7.3.275.0-82
Sources
euvd EUVD-2021-18467

Description

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234.

References