HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28827 | HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service. |
Fixes
Solution
Update PowerStation firmware version to x64.6.2.165, then reboot PowerStation.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6956-fbd85-1.html |
|
History
Wed, 19 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-02-19T16:27:37.410Z
Reserved: 2023-01-31T00:00:00.000Z
Link: CVE-2023-24837
Updated: 2024-08-02T11:03:19.288Z
Status : Modified
Published: 2023-03-27T04:15:09.830
Modified: 2024-11-21T07:48:29.740
Link: CVE-2023-24837
No data.
OpenCVE Enrichment
No data.
EUVD