cvedb.io
CVE-2021-33538
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2021-06-25T19:15:09.570 · Last modified 2026-06-17T03:54:44.930

Summary

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Affected products

weidmueller — ie-wl-bl-ap-cl-eu_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when weidmueller ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.