CVE-2021-47827 MEDIUM

CVE-2021-47827: WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service

Vendor Webssh
Product WebSSH for iOS
Weakness CWE-1284
Published January 16, 2026
Last update January 16, 2026

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash the application by pasting malformed input. Attackers can trigger the vulnerability by copying a 300-character buffer of repeated 'A' characters into the mashREPL input field, causing the application to crash.

Key dates

02Disclosure timeline

January 16, 2026 CVE published
January 16, 2026 Record updated