CVE-2021-26639

This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:wisa:smart_wing_cms:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

24 Aug 2022, 13:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:wisa:smart_wing_cms:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
References (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66875 - (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66875 - Third Party Advisory
CWE CWE-494
CWE-20

17 Aug 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-17 21:15

Updated : 2024-02-04 22:51


NVD link : CVE-2021-26639

Mitre link : CVE-2021-26639

CVE.ORG link : CVE-2021-26639


JSON object : View

Products Affected

wisa

  • smart_wing_cms

linux

  • linux_kernel
CWE
CWE-20

Improper Input Validation

CWE-494

Download of Code Without Integrity Check