CVE-2021-20141 is an unauthenticated command injection vulnerability affecting Gryphon Tower routers, specifically within the controller_server service. An unauthenticated remote attacker on the same network can achieve root-level command execution by sending a specially crafted packet to port 9999. This vulnerability carries a high CVSS score of 8.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, requiring only adjacent network access and no user interaction. While the EPSS score suggests a relatively low probability of exploitation compared to other CVEs, there is no public exploit code, Metasploit module, or significant community discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 04.0004.12CPE matchmatch criteria | cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.