A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272347.
History

Mon, 26 Aug 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared F-logic
F-logic datacube3
F-logic datacube3 Firmware
CPEs cpe:2.3:h:f-logic:datacube3:-:*:*:*:*:*:*:*
cpe:2.3:o:f-logic:datacube3_firmware:-:*:*:*:*:*:*:*
Vendors & Products F-logic
F-logic datacube3
F-logic datacube3 Firmware

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-07-24T11:00:09.075Z

Updated: 2024-08-01T21:52:31.414Z

Reserved: 2024-07-24T04:53:48.062Z

Link: CVE-2024-7066

cve-icon Vulnrichment

Updated: 2024-08-01T21:52:31.414Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-24T11:15:11.960

Modified: 2024-08-26T15:34:56.060

Link: CVE-2024-7066

cve-icon Redhat

No data.