← Vulnerability feed

Vulnerability record · CVE-2021-21924 · published 22 December 2021

CVE-2021-21924: Advantech r-seenet sql injection vulnerability

Advantech · R Seenet

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

6.5 CVSS 3.1 Medium EPSS 20% · top 2.6% CWE-89 · SQL injection
6.5CVSS 3.1 base score, v2 4.0
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21924 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5642Advantech r-seenet information exposure vulnerabilityAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…EPSS 17%9.8CVE-2023-2611Advantech r-seenet hard-coded credentials vulnerabilityAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a passwor…EPSS 0.67%9.8CVE-2022-3385Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…EPSS 1.3%9.8CVE-2022-3386Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…EPSS 1.3%9.8CVE-2021-21805Advantech R-SeeNet ping.php OS command injectionAdvantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS c…EPSS 70%analysed9.8CVE-2021-21804Advantech r-seenet php remote file inclusion vulnerabilityA local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…EPSS 3.7%8.8CVE-2021-21915Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%8.8CVE-2021-21916Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-21924), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.