Anyone with web_server enabled and HTTP basic auth configured on 2021.9.1 or older
web_server
allows OTA update without checking user defined basic auth username & password
Patch released in 2021.9.2
Disable/remove web_server
{ "nvd_published_at": "2021-09-28T16:15:00Z", "cwe_ids": [ "CWE-306" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-09-28T21:10:08Z" }