CVE-2021-42638 is a pre-authentication remote code execution vulnerability affecting PrinterLogic Web Stack versions 19.1.1.13 SP9 and below, stemming from a lack of user input sanitization. This high-severity flaw (CVSS 8.1) can be exploited remotely with high impact on confidentiality, integrity, and availability, requiring only high attack complexity. While not listed in CISA's KEV catalog, its EPSS score indicates a higher exploitability probability than 96% of all CVEs, and it has garnered some community discussion and media coverage, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.1.1.13CPE matchmatch criteria | cpe:2.3:a:printerlogic:web_stack:*:*:*:*:*:*:*:* | ||
19.1.1.13CPE matchmatch criteria | cpe:2.3:a:printerlogic:web_stack:19.1.1.13:-:*:*:*:*:*:* | ||
19.1.1.13CPE matchmatch criteria | cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp2:*:*:*:*:*:* | ||
19.1.1.13CPE matchmatch criteria | cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp3-3:*:*:*:*:*:* | ||
19.1.1.13CPE matchmatch criteria | cpe:2.3:a:printerlogic:web_stack:19.1.1.13:sp9:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.