Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2021-44148 | GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an … | Medium (6.1) | 2021-12-07 | Environment Specific |
| CVE-2021-40578 | Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in … | High (7.2) | 2021-12-07 | Environment Specific |
| CVE-2021-44149 | An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL S… | High (7.8) | 2021-12-07 | Environment Specific |
| CVE-2021-38759 | Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain … | Critical (9.8) | 2021-12-07 | Environment Specific |
| CVE-2021-36133 | The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in T… | High (7.1) | 2021-12-07 | Environment Specific |