← Back to browse · API

CVE-2021-33527

Severity
CRITICAL
CVSS
9.8
EPSS
0.04524
Risk score
40.78
CISA KEV
No
PoC
No
Published
2021-08-02
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-20219, GHSA-HRMP-939Q-G4MQ
Products
MB connect line:mbDIALUP 3.9R0.0 ≤3.9R0.0
Sources
euvd EUVD-2021-20219

Description

In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the service running with NT AUTHORITY\SYSTEM that will not correctly validate the input. This can lead to an arbitrary code execution with the privileges of the service.

References