PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).
References
| Link | Resource |
|---|---|
| https://starlabs.sg/advisories/21/21-35402/ |
Configurations
No configuration.
History
15 Apr 2026, 00:35
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
20 Feb 2026, 19:23
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 19:23
Updated : 2026-04-15 00:35
NVD link : CVE-2021-35402
Mitre link : CVE-2021-35402
CVE.ORG link : CVE-2021-35402
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
