← Vulnerability feed

Vulnerability record · CVE-2021-33393 · published 9 June 2021

CVE-2021-33393: IPFire backup script ownership flaw enables root code execution

Ipfire · Ipfire

IPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. An attacker who can modify it can plant a Trojan horse script that root later executes. The advisory notes similar ownership or permission problems may exist on other files.

8.8 CVSS 3.1 High EPSS 60% · top 0.9%
8.8CVSS 3.1 base score, v2 9.0
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by an unprivileged account, which could potentially be used to install a Trojan horse backup.pl script that is later executed by root. Similar problems with the ownership/permissions of other files may be present as well.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 8.8 with low-privilege network reach, public exploit code and very high EPSS make this a serious root-compromise risk despite no KEV listing.

What it is

IPFire 2.25-core155 does not verify that /var/ipfire/backup/bin/backup.pl is owned by root, so the file may be writable by an unprivileged account. An attacker who can modify it can plant a Trojan horse script that root later executes. The advisory notes similar ownership or permission problems may exist on other files.

Impact

An attacker with a low-privileged account gains arbitrary code execution as root on the IPFire system, giving full control of the firewall and any data or traffic it handles.

Attack surface

The flaw is network-reachable per the CVSS vector (AV:N) and requires low privileges (PR:L) with no user interaction (UI:N). The attacker needs an account or access path that can write to the backup script or another mis-owned file.

Exploitation

CISA KEV does not list this CVE, but public exploit code exists in the references and EPSS is very high (0.587, 99th percentile), indicating elevated real-world exploitation likelihood.

What to do

  • Apply the vendor patch commit 6769d909306d7bdc43d64598872126fcf1b217f6 or upgrade IPFire to a release containing it.
  • Verify and correct ownership and permissions on /var/ipfire/backup/bin/backup.pl and other files under /var/ipfire so only root can write them.
  • Restrict and audit accounts with shell or file access on the IPFire host; remove unnecessary unprivileged users.
  • Monitor the backup script and related paths for unexpected content or ownership changes.
  • Review the full /var/ipfire tree for similar ownership or permission weaknesses noted in the advisory.

Detection

  • Alert on ownership or permission changes to /var/ipfire/backup/bin/backup.pl and other /var/ipfire files.
  • Monitor for unexpected modifications to backup.pl content or new files in the backup bin directory.
  • Watch for root-owned process execution originating from backup.pl or the backup cron path outside scheduled windows.
  • Correlate low-privileged account activity with writes into /var/ipfire paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-33393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-16232Ipfire os command injection vulnerabilityAn authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated us…EPSS 7.8%8.8CVE-2017-9757Ipfire os command injection vulnerabilityIPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited…EPSS 37%8.7CVE-2025-34311Ipfire os command injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …EPSS 14%8.7CVE-2025-34312Ipfire os command injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary …EPSS 2.3%7.1CVE-2025-34304Ipfire sql injection vulnerabilityIPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL que…EPSS 0.39%6.5CVE-2025-50974Ipfire os command injection vulnerabilityThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating p…EPSS 0.40%6.1CVE-2025-50976Ipfire cross-site scripting vulnerabilityIPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query param…EPSS 0.23%6.1CVE-2020-21142Ipfire cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2021-33393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.