Impact
The flaw allows an authenticated attacker to write arbitrary shell scripts to a writable area of persistent storage and then endpoint. Because the vulnerability persists across device reboots, a successful compromise would grant an adversary continued remote control. This weakness is categorized as an interpreter/engine execution fault (CWE‑94).
Affected Systems
JAIOTlink C492A‑W6 firmware version 4.8.30.57701411 are confirmed to be affected. No other vendors, products, or firmware revisions were identified.
Risk and Exploitability
The base CVSS score of 7.7 indicates a high‑severity issue. The EPSS score of less than 1% shows a very low but non‑zero likelihood of exploitation. Attackers must first obtain authentication credentials, likely through local network access or credential theft, before triggering the endpoint. Once exploited, the malicious script runs with the device’s privileges, allowing the attacker to maintain persistent control. The vulnerability is not listed in the CISA KEV catalog, so no widespread active exploitation is presently documented.
OpenCVE Enrichment