The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities.
Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices.

This issue affects DVW-W02W2-E2 through version 2.5.2.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32439 The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.
Fixes

Solution

Since DVW-W02W2 is no longer in production and maintenance, Delta decided not to patch these vulnerabilities. There is no solution.


Workaround

Since DVW-W02W2 is no longer in production and maintenance, Delta decided not to patch these vulnerabilities. There is no workaround.

References
Link Providers
https://onekey.com/ cve-icon cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ONEKEY

Published:

Updated: 2024-08-01T20:26:57.142Z

Reserved: 2024-04-16T08:01:45.912Z

Link: CVE-2024-3871

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.142Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-16T09:15:08.630

Modified: 2024-11-21T09:30:36.063

Link: CVE-2024-3871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.