Vulnerability Database

310,450

Total vulnerabilities in the database

CVE-2021-4470

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.

  • Published: Nov 14, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-4470
  • Exploit:

No technical information available.

CWEs:

OWASP TOP 10: