Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-48476 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 28 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Alientechnology alr-f800 Firmware
         | 
|
| CPEs | cpe:2.3:h:alientechnology:alr-f800:-:*:*:*:*:*:*:* cpe:2.3:o:alientechnology:alr-f800_firmware:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Alientechnology alr-f800 Firmware
         | 
Wed, 07 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Alientechnology
         Alientechnology alr-f800  | 
|
| CPEs | cpe:2.3:a:alientechnology:alr-f800:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Alientechnology
         Alientechnology alr-f800  | 
|
| Metrics | 
        
        ssvc
         
  | 
Wed, 07 Aug 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Alien Technology ALR-F800 File Name upgrade.cgi popen os command injection | |
| Weaknesses | CWE-78 | |
| References | 
         | |
| Metrics | 
        
        cvssV2_0
         
 
 
 
  | 
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-07T15:24:06.724Z
Reserved: 2024-08-07T06:37:55.279Z
Link: CVE-2024-7579
Updated: 2024-08-07T15:23:56.430Z
Status : Analyzed
Published: 2024-08-07T14:15:33.380
Modified: 2024-08-28T18:26:46.117
Link: CVE-2024-7579
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD