Impact
This vulnerability is a code injection flaw that allows an attacker to inject and execute arbitrary code. The flaw enables full compromise of the affected device, giving the attacker control over system processes and data. The weakness is a classic example of improper control of code generation, classified under CWE-94.
Affected Systems
Klemsan Electrical Electronics Inc. offers KIO (Klemsan Internet Objects) firmware versions prior to 1.9. These versions do not contain any mitigation for the described injection flaw, leaving them exposed.
Risk and Exploitability
The CVSS base score of 9.8 signifies critical severity. EPSS data is unavailable, but the flaw is listed as not in CISA KEV, indicating no known active exploitation yet. The adaptation in the title indicates an unauthenticated path; the likely attack vector is remote execution from a client with network access to the device. No further exploit conditions are detailed in the available information.
OpenCVE Enrichment