MEDIUM
CVE-2021-20035
CVSS
6.5
KEV
Description
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Summary dbcve.org
Command injection vulnerability in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary shell commands, which execute with the privileges of the 'nobody' user, potentially leading to denial of service.
Mitigation
Implement proper input validation and sanitization for all user-supplied parameters in the SMA100 management interface to prevent command injection attacks.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
4.18%
Probability of exploitation in next 30 days
90.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.