Vulnerability record · CVE-2021-21805 · published 5 August 2021
CVE-2021-21805: Advantech R-SeeNet ping.php OS command injection
Advantech · R Seenet
Advantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS command execution on the host. The vulnerability is remotely reachable and requires no authentication, making it a serious risk for exposed instances.
Description
An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary OS command execution. An attacker can send a crafted HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and a very high EPSS score indicate an easily exploitable, high-impact remote command execution flaw.
What it is
Advantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS command execution on the host. The vulnerability is remotely reachable and requires no authentication, making it a serious risk for exposed instances.
Impact
An attacker gains arbitrary OS command execution with the privileges of the web server process, enabling full compromise of the R-SeeNet host. This can lead to data theft, lateral movement, or service disruption.
Attack surface
Reached over the network via HTTP requests to the ping.php script; the CVSS vector shows no privileges required and no user interaction. Any internet- or network-exposed R-SeeNet instance is directly reachable.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.698 probability, 99.3rd percentile) and the vendor advisory reference is tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.
What to do
- Apply the vendor patch or upgrade R-SeeNet beyond v2.4.12 (20.10.2020) as advised by Advantech.
- Restrict network access to the R-SeeNet web interface using firewall rules or a VPN; do not expose it to the internet.
- Run the web service under a low-privilege account and apply least-privilege filesystem permissions.
- Monitor and review the ping.php endpoint for unexpected or malformed input parameters.
- If patching is not immediately possible, consider disabling or blocking the ping.php functionality until a fix is applied.
Detection
- Inspect web server and application logs for suspicious requests to ping.php containing shell metacharacters or command separators.
- Monitor for unexpected child processes spawned by the web server (e.g., cmd.exe, /bin/sh, ping) with unusual arguments.
- Use network detection to flag HTTP requests to ping.php with encoded or unusual parameter values.
- Alert on outbound connections or file writes originating from the R-SeeNet host process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1274 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1274 | ExploitThird Party Advisory |
Track CVE-2021-21805 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21805), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.