Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command.
History

Wed, 20 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Rakuten
Rakuten turbo 5g Firmware
CPEs cpe:2.3:o:rakuten:turbo_5g_firmware:*:*:*:*:*:*:*:*
Vendors & Products Rakuten
Rakuten turbo 5g Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-11-20T07:30:10.357Z

Updated: 2024-11-20T15:16:26.650Z

Reserved: 2024-11-05T02:54:12.661Z

Link: CVE-2024-48895

cve-icon Vulnrichment

Updated: 2024-11-20T15:07:08.501Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-20T08:15:15.190

Modified: 2024-11-21T13:57:24.187

Link: CVE-2024-48895

cve-icon Redhat

No data.