CVE-2021-40859 describes critical backdoors in Auerswald COMpact 5500R 7.8A and 8.0B devices, allowing unauthenticated attackers full administrative access via the web management interface. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit code is publicly available on ExploitDB and Nuclei templates exist, indicating a high potential for exploitation, further supported by its high EPSS score and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.8aCPE matchmatch criteria | cpe:2.3:o:auerswald:compact_5500r_firmware:7.8a:build002:*:*:*:*:*:* | ||
8.0bCPE matchmatch criteria | cpe:2.3:o:auerswald:compact_5500r_firmware:8.0b:build000:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.