Impact
3onedata's GW1101-1D(RS-485)-TB-P modbus gateway contains a command injection flaw in the diagnosis test tools. An attacker who can authenticate to the gateway and provide malicious input in the IP address field can cause the device to run arbitrary shell commands as the root user. The flaw gives the attacker system-level privileges and the ability to execute any commands on the device.
Affected Systems
The vulnerability applies to 3onedata GW1101-1D(RS-485)-TB-P modbus gateways with hardware version V2.2.0 that are running firmware versions older than 3.0.59B2024080600R4353. Devices updated to firmware 3.0.59B2024080600R4353 or later are not affected.
Risk and Exploitability
The flaw has a CVSS score of 9.3, indicating critical severity. It requires authenticated access to the diagnostic test tools, meaning only users with valid credentials may exploit it. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. Given its high severity and the potential for root-level command execution, prompt remediation is advised.
OpenCVE Enrichment