CVE-2021-42912 - CVE House
Back to Database
Status published High CVE-2021-42912

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS...

Vulnerability Description

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42912

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

an5506-01-a firmware, an5506-01-b firmware, an5506-02-b firmware, an5506-04-b firmware, an5506-04-f firmware, aan5506-04-g2g firmware
Vulnerable Versions:
rp0509, rp2610, rp2520, rp2521, rp2603, rp2510, rp2617, rp2560

Timeline

Official Publish: December 16th, 2021
Last Modified: July 9th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.