CVE-2021-35402Disclosure

LOWCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-20: 2Mentions · 2026-04-11: 1Active Exploitation · 2026-04-11: 1Technical Details · 2026-02-20: 2Technical Details · 2026-04-11: 102-2004-11
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-202
Disclosure2
2026-04-111
Active Exploitation1
Full discourse3 posts
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2021-35402 Exploit in the wild confirmed for CVE-2021-35402 (CVSS 10.0). PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS c... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post reports confirmed live exploitation of CVE-2021-35402 with a CVSS 10.0 score and a specific vulnerability location, but it provides no PoC, exploit code, or patch information.

    0000071
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2021-35402: CRITICAL] PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).#cve,CVE-2021-35402,#cybersecurity https://cvefind.com/CVE-2021-35402

    Post summary

    The text discloses a critical OS command injection vulnerability in PROLiNK PRC2402M firmware (before 2021‑06‑13) through live_api.cgi’s satellite_list page; no PoC, exploit, patch, or active exploitation is reported.

    0000043
    578 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2021-35402** pertains to a critical command injection vulnerability in the PROLiNK PRC2402M router firmware versions prior to 2021-06-13. Specifically, the flaw exists within the `live_api.cgi` script, which processes the `page=satellite_list` request. An attacker can exploit this vulnerability by injecting malicious shell metacharacters into the `ip` parameter of the `satellite_status` function, leading to arbitrary OS command execution on the device. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2021-35402

    Post summary

    The post details a critical command injection flaw in PROLiNK PRC2402M routers, outlining the exact vulnerability vector and impact without providing PoC, exploit code, or patch information.

    0000032
    20 followersView on X

Explore more