Back to Database
Status published
Medium
CVE-2021-40858
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure....
Vulnerability Description
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-40858
Credits & Attribution
No credits recorded in the NVD database.
References
More from auerswald
View All →CVE-2021-40859
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B...
Critical
9.8
CVE-2021-40857
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via...
High
8.8
CVE-2021-40856
Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices...
High
7.5
CVE-2018-19978
A buffer overflow vulnerability in the DHCP and PPPOE configuration...
High
8
CVE-2018-19977
A command injection (missing input validation, escaping) in the ftp...
High
8
Affected Vendor
auerswald
View all reports →Affected Software
compact 5500r ip firmware, compact 5200r ip firmware, compact 5000r ip firmware, compact 4000 ip firmware, commander 6000r ip firmware, commander 6000rx ip firmware, commander business\(19\"\) ip firmware, commander basic.2\(19\"\) ip firmware, compact 5010 voip ip firmware, compact 5020 voip ip firmware
Vulnerable Versions:
0
Timeline
Official Publish:
December 13th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.