CVE-2024-9166

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Sep 2024, 12:46

Type Values Removed Values Added
Summary
  • (es) El dispositivo permite que un atacante no autorizado ejecute comandos del sistema con privilegios elevados. Esta vulnerabilidad se facilita mediante el uso de la consulta 'getcommand' dentro de la aplicaciĆ³n, lo que permite al atacante obtener acceso superusuario.

26 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 17:15

Updated : 2024-09-30 12:46


NVD link : CVE-2024-9166

Mitre link : CVE-2024-9166

CVE.ORG link : CVE-2024-9166


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')