Pricing
Contact
Login
Start Free Trial
Research Center
CVE-2021-45876 Research Center
topia vulnerability management banner 11.png

CVE-2021-45876

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.

  • 9.8 critical severity
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • 21/03/2022

Operating Systems 3

Wa

Wallbox GTB Firmware

by Garo

2 Versions

24 days ago

Wa

Wallbox GTC Firmware

by Garo

2 Versions

24 days ago

Wa

Wallbox GLB Firmware

by Garo

2 Versions

24 days ago

Vulnerability Categories 1

Improper Neutralization of Special Elements used in a Command ('Command Injection')

xTags 7

#easy_to_exploit
#critical_vulnerability
#known_vulnerability
#confidentiality_impact_if_exploited
#integrity_impact_if_exploited
#availability_impact_if_exploited
#new_vulnerability_published

Advisory Links 1

https://github.com/delikely/advisory/tree/main/GARO
http://www.vicarius.io is owned and operated by Vicarius Ltd. (the “Company”). All information contained on the Website is purely for informational, and educational purposes and should be independently verified and confirmed. Vicarius does not accept any liability for any loss or damage whatsoever caused in reliance upon such information or services. No statements or information presented in any form by Vicarius is intended as fact, and you agree that you will not consider the statements or information presented on the Website as fact or as a guarantee of performance.

Related CVEs

Security Research Topics

By Paul Lighter
Jan 11, 2023

When the Target is Also the Threat

A software failure grounded thousands of flights today, raising a complicated question - how do you secure an unstable system? The answer has never been more urgent.
By Paul Lighter
Jan 06, 2023

The Uncomfortable Implications of the LastPass Attack

The recent attack on LastPass has people questioning if they can trust password managers. But there's a bigger issue lurking underneath - can you trust ANY security vendor?
By Paul Lighter
Nov 30, 2022

Online Casino Heist Shreds Confidence in Cybersecurity

Hackers recently swiped $300,000 from DraftKings accounts - and it was almost effortless. This attack will likely be forgotten by history. But it should be a wake-up call instead.
By Mohammad Hussam Alzeyyat
Nov 29, 2022

Ethernaut CTF - Vault Challenge

Here we are with the Vault challenge from Ethernaut CTF. We are going to be introduced to the NON Privacy on-chain and how we should not store secrets and critical information into variables even if we set the type of those variables as private. We will see how we can extract the values of those private variables.
By Mohammad Hussam Alzeyyat
Nov 18, 2022

DownUnderCTF 2022 Blockchain - Crypto Casino

In this blog, we are going to hack the casino contract of the DownUnderCTF 2022 challenges. There is a PRNG function that we are going to exploit it using a python script. Don't forget Hackers Gonna Hack!
last_chanse_04.png

Start Closing Security Gaps

  • Risk reduction from Day 1
  • Fast set-up and deployment
  • Unified platform
  • Full-featured 14-day trial
Get a Demo
Start Free Trial!

Have questions?

By submitting this form, you agree to be contacted about TOPIA and other Vicarius products.

Vicarius develops an autonomous vulnerability remediation platform to help security teams protect their assets against software exploitation. Consolidating vulnerability assessment, prioritization, and remediation, Vicarius strengthens cyber hygiene and proactively reduces risk.
We're hiring!

Support

support@vicarius.io

Sales

sales@vicarius.io

Marketing

info@vicarius.io
Product
Product Overview
Vulnerability Management
Patch Management
Patchless Protection
Auto Actions
Network Scanner
xTags
0-Day Detection
Solution
Solution Overview
Case Studies
Knowledge
Research Center
Apps & OS Patch Catalog
Videos
Articles
Docs
Company
About
Investors
Partners
Trust
Careers
Pricing
Pricing
Compare
TOPIA vs. Automox
TOPIA vs. ManageEngine
TOPIA vs. Rapid7
TOPIA vs. Tenable
TOPIA vs. Tanium
TOPIA vs. RMMs
TOPIA vs. Vulcan
TOPIA vs. PDQ
TOPIA vs. Qualys

Copyright © Vicarius. All rights reserved 2022. Privacy Policy and Terms of Use