CVE-2021-38453
Some API functions allow interaction with the registry, which includes reading values as well as data modification.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 0.25%
- CWE
- CWE-15
- Published
- 2021-10-22
- Last modified
- 2026-03-13
Affected products
- AUVESY Versiondog
Weakness type
Related vulnerabilities
- CVE-2024-4326 — Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui
- CVE-2026-6973 — An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
- CVE-2023-46248 — Overwrite of builtin Cody commands facilitates RCE
- CVE-2024-39800 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39799 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39798 — Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli
- CVE-2024-39795 — Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000
- CVE-2024-39794 — Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000