CVE-2021-20991 is a high-severity command injection vulnerability affecting Fibaro Home Center 2 and Lite devices running firmware version 4.540 and older. An authenticated attacker can exploit this flaw to execute arbitrary commands with root privileges, leading to complete compromise of the device (Confidentiality, Integrity, and Availability impacts are High). The vulnerability has a CVSS score of 8.8, indicating a high risk, and an EPSS score suggesting it is more exploitable than 96.9% of all CVEs. While no public exploit code or active exploitation has been observed, and there is minimal community discussion, the potential for severe impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.540CPE matchmatch criteria | cpe:2.3:o:fibaro:home_center_2_firmware:*:*:*:*:*:*:*:* | ||
<= 4.540CPE matchmatch criteria | cpe:2.3:o:fibaro:home_center_lite_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.