← Back to browse · API

CVE-2021-37912

Severity
CRITICAL
CVSS
9.8
EPSS
0.02832
Risk score
40.19
CISA KEV
No
PoC
No
Published
2021-09-15
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-24390, GHSA-9WV9-VHVP-XJXR
Products
Hgiga:OAKlouds OAKSv2 OAKlouds-network 2.0 ≤OAKlouds-network-2.0-2, Hgiga:OAKlouds OAKSv3 OAKlouds-network 3.0 ≤OAKlouds-network-3.0-2
Sources
euvd EUVD-2021-24390

Description

The HGiga OAKlouds mobile portal does not filter special characters of the Ethernet number parameter of the network interface card setting page. Remote attackers can use this vulnerability to perform command injection and execute arbitrary commands in the system without logging in.

References