← Vulnerability feed

Vulnerability record · CVE-2021-21915 · published 22 December 2021

CVE-2021-21915: Advantech r-seenet sql injection vulnerability

Advantech · R Seenet

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

8.8 CVSS 3.1 High EPSS 1.4% · top 29.0% CWE-89 · SQL injection
8.8CVSS 3.1 base score, v2 6.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21915 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5642Advantech r-seenet information exposure vulnerabilityAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…EPSS 17%9.8CVE-2023-2611Advantech r-seenet hard-coded credentials vulnerabilityAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a passwor…EPSS 0.67%9.8CVE-2022-3385Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…EPSS 1.3%9.8CVE-2022-3386Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…EPSS 1.3%9.8CVE-2021-21805Advantech R-SeeNet ping.php OS command injectionAdvantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS c…EPSS 70%analysed9.8CVE-2021-21804Advantech r-seenet php remote file inclusion vulnerabilityA local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…EPSS 3.7%8.8CVE-2021-21916Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%8.8CVE-2021-21917Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-21915), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.