Impact
A flaw in iStoreOS version 24.10.7 and earlier allows a remote attacker to execute arbitrary code by providing a malicious value in the task_id parameter within the tasks-lib.lua script. The vulnerability can lead to full system compromise, granting the attacker control over the affected device. The weakness stems from insufficient validation of the task_id argument, enabling unintended code execution. If exploited, confidentiality, integrity, and availability of the device and any connected services could be severely affected.
Affected Systems
The affected product is iStoreOS, specifically releases 24.10.7 and earlier. The vulnerability resides in the tasks-lib.lua component used to handle task identifiers. No other vendors or versions are mentioned.
Risk and Exploitability
The flaw permits arbitrary code execution, representing a high severity risk. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, concrete exploitation statistics are missing; however, the nature of the flaw strongly suggests it could be actively exploited. The attack vector is remote, likely via an unauthenticated HTTP request to the router’s task management endpoint. An attacker only needs to supply a crafted task_id value to trigger arbitrary code execution.
OpenCVE Enrichment