Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/yckuo-sdc/PoC |
History
Tue, 27 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-14T00:00:00
Updated: 2024-08-27T18:56:01.133Z
Reserved: 2024-01-25T00:00:00
Link: CVE-2024-24301
Vulnrichment
Updated: 2024-08-01T23:19:52.026Z
NVD
Status : Awaiting Analysis
Published: 2024-02-14T23:15:08.190
Modified: 2024-08-27T19:35:12.480
Link: CVE-2024-24301
Redhat
No data.