CVE-2021-20144
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2021-20144. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.
Available Exploits
Related News
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
References
Advisory provided by GitHub Security Advisory Database. Published: December 10, 2021, Modified: December 14, 2021