PT-2024-20256 · Monoprice · Monoprice Select Mini V2
Published
2024-06-12
·
Updated
2024-11-20
·
CVE-2024-24051
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Monoprice Select Mini V2 version V37.115.32
Description
The issue arises from improper input validation of printing files, allowing attackers to instruct the device's movable parts to destinations beyond the device's maximum coordinates. This can be achieved by printing a malicious .gcode file.
Recommendations
For Monoprice Select Mini V2 version V37.115.32, consider validating all .gcode files before printing to prevent malicious instructions from being executed. As a temporary workaround, restrict access to the printing functionality until a proper fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Monoprice Select Mini V2