CVE-2021-4473 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 7, 2026
Tianxin Internet Behavior Management System - Command Injection
Published: April 7, 2026Updated: April 7, 2026KEVRemote Exploitable
Overview
Tianxin Internet Behavior Management System contains a command injection caused by crafted objClass parameter in Reporter component endpoint, letting unauthenticated attackers execute arbitrary commands and write malicious PHP files, exploit requires no authentication.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can execute arbitrary commands and achieve remote code execution with web server privileges.
Mitigation
Update to version NACFirmware_4.0.0.7_20210716.180815_topsec_0_basic.bin or later.
References
- https://avd.aliyun.com/detail?id=AVD-2021-890232
- https://cn-sec.com/archives/4631959.html
- https://www.cnvd.org.cn/flaw/show/CNVD-2021-41972
- https://www.cnvd.org.cn/patchInfo/show/280166
- https://www.vulncheck.com/advisories/tianxin-internet-behavior-management-system-command-injection-via-toquery-php
- https://www.cve.org/CVERecord?id=CVE-2021-4473
Related Resources
Details
- CVE ID
- CVE-2021-4473
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
CWE
- CWE-78
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H