← Vulnerability feed

Vulnerability record · CVE-2021-40870 · published 13 September 2021

CVE-2021-40870: Aviatrix Controller unauthenticated file upload leads to RCE

Aviatrix · Controller

Aviatrix Controller 6.x before 6.5-1804.1922 allows unrestricted upload of a dangerous file type, and directory traversal lets an unauthenticated attacker place and execute arbitrary code. The flaw is remotely reachable with no credentials or user interaction, making it a direct path to full compromise of the controller.

9.8 CVSS 3.1 Critical CISA KEV since 18 Jan 2022 EPSS 93% · top 0.2% CWE-23 · Relative path traversal
9.8CVSS 3.1 base score, v2 7.5
93%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, KEV listing, and near-maximum EPSS probability makes this an urgent patch.

What it is

Aviatrix Controller 6.x before 6.5-1804.1922 allows unrestricted upload of a dangerous file type, and directory traversal lets an unauthenticated attacker place and execute arbitrary code. The flaw is remotely reachable with no credentials or user interaction, making it a direct path to full compromise of the controller.

Impact

An attacker gains remote code execution on the Aviatrix Controller, which can lead to full control of the controller and the network infrastructure it manages.

Attack surface

Reachable over the network via the controller's web interface; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt the upload and traversal.

Exploitation

Listed in CISA KEV since 2022-01-18 with a required action to apply vendor updates, and EPSS 30-day probability is 0.93 (99.8th percentile). Public exploit references are tagged Exploit, indicating working exploit code is available.

What to do

  • Upgrade Aviatrix Controller to 6.5-1804.1922 or later per the vendor release notes.
  • If immediate patching is not possible, restrict network access to the controller management interface to trusted hosts only.
  • Monitor and block directory traversal patterns and unexpected file uploads at the perimeter or WAF.
  • Rotate credentials and review controller logs for signs of compromise after exposure.
  • Verify no unauthorized files or processes were placed on the controller before remediation.

Detection

  • Inspect controller and web server logs for upload requests containing traversal sequences such as ../ or encoded variants.
  • Alert on file creation in web-accessible or executable directories outside expected deployment paths.
  • Monitor for unexpected outbound connections or new processes spawned by the controller service.
  • Hunt for known exploit request patterns against the controller endpoint using the public advisory indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-40870 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Aviatrix Controller Unrestricted Upload of File". Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-40870 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-50603Aviatrix Controller unauthenticated OS command injectionAviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996 fails to neutralize shell metacharacters passed to the /v1/api endpoint, allowing OS co…KEVEPSS 99%analysed9.8CVE-2020-26553Aviatrix controller unrestricted file upload vulnerabilityAn issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web …EPSS 1.8%9.8CVE-2020-13417Aviatrix controller vulnerabilityAn Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Lin…EPSS 2.3%8.8CVE-2020-26548Aviatrix controller vulnerabilityAn issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any u…EPSS 1.5%8.8CVE-2020-13412Aviatrix controller cross-site request forgery vulnerabilityAn issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, lead…EPSS 0.58%7.5CVE-2020-27568Aviatrix controller incorrect permission assignment vulnerabilityInsecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. …EPSS 1.6%7.5CVE-2020-26549Aviatrix controller vulnerabilityAn issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed…EPSS 1.5%7.5CVE-2020-26550Aviatrix controller vulnerabilityAn issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a thre…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2021-40870), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.