CVE-2021-4473 is a command injection vulnerability in the Tianxin Internet Behavior Management System's Reporter component that allows unauthenticated attackers to execute arbitrary commands remotely by manipulating the objClass parameter with shell metacharacters. The vulnerability enables adversaries to write malicious PHP files to the web root and achieve remote code execution with web server privileges. This issue was remediated in firmware version NACFirmware_4.0.0.7_20210716.180815_topsec_0_basic.bin. The vulnerability carries a CVSS v3.1 score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. It poses a complete compromise of confidentiality, integrity, and availability of affected systems. The EPSS score of 0.0083 indicates this threat is not currently prevalent in the wild relative to other CVEs. Exploitation evidence was first documented by the Shadowserver Foundation on June 1, 2024. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, suggesting limited active exploitation in the threat landscape at this time. Organizations operating affected Tianxin systems should prioritize patching to mitigate this critical remote code execution risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0.7_20210716.180815CPE matchmatch criteria | cpe:2.3:a:topsecgroup:tianxin_internet_behavior_management_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.