PT-2024-16040 · Secom · Secom Wrtr-304Gn-304Tw-Upsc

Anwei Kung

+4

·

Published

2024-10-17

·

Updated

2024-10-18

·

CVE-2024-10118

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SECOM WRTR-304GN-304TW-UPSC (affected versions not specified)
Description The issue is related to improper filtering of user input in a specific functionality, allowing unauthenticated remote attackers to inject and execute arbitrary system commands on the device. This can be exploited by attackers to gain unauthorized access and control over the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10118

Affected Products

Secom Wrtr-304Gn-304Tw-Upsc