S4E just found a high-severity finding from ssl robot vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2025

CVE-2021-45420 Scanner

CVE-2021-45420 Scanner - Arbitrary File Write vulnerability in Emerson Dixell XWEB-500

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-45420
9.8
CVSS

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Emerson Dixell XWEB-500 is a system typically used in monitoring and managing refrigeration units and HVAC (Heating, Ventilation, and Air Conditioning) systems. It is utilized by various businesses such as retail stores, warehouses, and manufacturers to ensure the efficacy of their cooling systems. Contractors and building managers use these systems for real-time data logging, alarm notifications, and system performance analysis. The system interface allows users to remotely configure and monitor connected devices, providing critical insights into energy consumption and system diagnostics. Common in facilities that prioritize energy management and optimal equipment performance, Emerson Dixell XWEB-500 plays a vital role in operational efficiency. Its deployment supports the seamless integration of refrigeration management into larger building management systems.

Arbitrary File Write vulnerabilities occur when an attacker can write or overwrite arbitrary files on a system. This vulnerability in Emerson Dixell XWEB-500 is especially critical since no authentication is required to exploit it. Attackers can gain unauthorized access through specific CGI scripts within the system, such as "/cgi-bin/logo_extra_upload.cgi". Once access is obtained, they can write files to the system. Such vulnerabilities put the entire system at risk because it allows for further exploitation such as planting malware or modifying configuration files. Consequently, the vulnerability could lead to a complete system compromise if not addressed properly.

The Arbitrary File Write vulnerability present in Emerson Dixell XWEB-500 is specifically located in CGI scripts that do not properly validate access control. Critical endpoints include "/cgi-bin/logo_extra_upload.cgi", "/cgi-bin/cal_save.cgi", and "/cgi-bin/lo_utils.cgi". These scripts allow attackers to upload crafted files without the need for authentication. The vulnerability affects the file upload mechanism, where the data written to files is not adequately sanitized. This oversight leads to the ability to overwrite important system files, thus escalating the potential for further attacks such as remote command execution or data theft.

Exploiting this vulnerability could lead to several serious implications. The attacker might upload and execute malicious files, which can disrupt normal operations and compromise sensitive data. System integrity and availability can be jeopardized, potentially bringing critical processes reliant on HVAC and refrigeration to a halt. Sensitive infrastructure data might be accessed or deleted, resulting in data breaches. Additionally, compromised systems could become conduits for further attacks within the network.

REFERENCES

Solution Advice
  • Upgrade Emerson Dixell XWEB-500 to the latest firmware to address the vulnerability.
  • Implement network-level access controls to restrict unauthorized access to the system.
  • Regularly audit system configurations to identify and address security weaknesses.
  • Apply proper input validation and authentication mechanisms to all exposed scripts.
  • Ensure continuous monitoring for any unauthorized file write attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.