Security readout for executives and security teams
Plain-English summary
A ProLink PRC2402M router running firmware V1.0.18 or older can mishandle a TR-069 local port value in its administration CGI. The value is passed to the operating system, creating command injection risk. Business urgency depends on whether these routers exist in the environment and whether their admin interface is reachable by untrusted users.
Executive priority
Prioritize discovery and access restriction before broader remediation. This is high concern for exposed or unmanaged routers because command injection can affect device control, but source evidence is incomplete on exploitation and fixes.
Technical view
CVE-2021-36705 is a command injection flaw in the set_TR069 function of adm.cgi on ProLink PRC2402M V1.0.18 and older. The CVE description says TR069_local_port is passed directly to system when the TR069 page path is used. The sources do not provide CVSS, CWE, authentication details, or vendor remediation specifics.
Likely exposure
Exposure is limited to organizations using ProLink PRC2402M devices on firmware V1.0.18 or older. Risk is materially higher if the device administration interface is internet-facing, reachable from guest networks, or accessible to compromised internal hosts.
Exploitation context
The source bundle does not show CISA KEV listing or other evidence of active exploitation. Public disclosure exists from a researcher write-up. The sources do not establish whether authentication is required, whether a patch exists, or how commonly the model is deployed.
Researcher notes
The strongest technical evidence is the CVE description and linked Ayrx disclosure naming adm.cgi, set_TR069, and TR069_local_port. Missing details include CVSS vector, authentication requirements, exploit prevalence, vendor acknowledgement, and fixed versions. Treat internet-exposed management as the primary validation focus.
Mitigation direction
- Inventory ProLink PRC2402M routers and record firmware versions.
- Check ProLink or supplier guidance for fixed firmware or replacement advice.
- Restrict administrative access to trusted management networks or VPN only.
- Disable or tightly restrict TR-069 management if not operationally required.
- Replace unsupported affected devices if no vendor fix is available.
Validation and detection
- Confirm whether any PRC2402M device runs V1.0.18 or older.
- Verify admin interfaces are not reachable from the public internet.
- Review firewall rules separating router management from user networks.
- Check configuration and logs for unexpected TR-069 setting changes.
- Track vendor advisories for remediation status and firmware availability.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-36705 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.ayrx.me/prolink-prc2402m-multiple-vulnerabilities/#tr069-command-injectionCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
