ID:7048 - Exploit for Improper access control in SMA 100 - CVE-2021-20034
Published: November 25, 2021
SMA 100
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to delete arbitrary files on the system.
The vulnerability exists due to improper access restrictions in SMA 100 management interface. A remote non-authenticated attacker can bypass implemented path traversal checks and delete an arbitrary file on the system, potentially resulting in a reboot to factory default settings.