S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-21802 Scanner

CVE-2021-21802 scanner - Code Injection vulnerability in Advantech R-SeeNet

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21802
6.1
CVSScritical
Exploitable remotely over the internet · no authentication required · user interaction needed.

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Advantechby n/a
Advantech R-SeeNet 2.4.12 (20.10.2020)
Updated Aug 21, 2026View on NVD →
Detail

R-SeeNet is a web-based management software developed by Advantech that allows users to monitor and control their remote devices and systems. This software is particularly useful in industrial settings where there are multiple devices that require remote access and control. With R-SeeNet, users can easily manage their devices through a web-browser interface, avoiding the need for manual configuration or on-site visits.

The CVE-2021-21802 vulnerability detected in the R-SeeNet software is a critical security flaw that allows attackers to execute arbitrary JavaScript code on the victim's device. Specifically, the vulnerability is present in the device_graph_page.php script, which is a part of the software. With a specially crafted URL, an attacker can exploit this vulnerability and gain control of the victim's system or steal sensitive information.

When exploited, the CVE-2021-21802 vulnerability can lead to devastating consequences for the victim. An attacker can execute malicious code on the victim's device, allowing them to gain access to confidential information, disrupt operations, or even cause physical harm. For industrial settings that rely on R-SeeNet for remote management, an attack on this level could have enormous financial and reputational impacts.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. With advanced scanning and reporting tools, this platform is a powerful tool for identifying potential vulnerabilities and risks in any online system or application. By taking advantage of these features, organizations can minimize their risk exposure and protect their digital assets from malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken. These include:

  • Applying the latest security patches and updates to the R-SeeNet software.
  • Restricting access to the device_graph_page.php script to trusted users only.
  • Regularly monitoring network traffic for any suspicious activity.
  • Utilizing strong password policies and multi-factor authentication.
  • Implementing intrusion detection and prevention systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.