CVE-2024-24301

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/yckuo-sdc/PoCĀ - () https://github.com/yckuo-sdc/PoCĀ -

27 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

14 Feb 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 23:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24301

Mitre link : CVE-2024-24301

CVE.ORG link : CVE-2024-24301


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')