PT-2024-20298 · Telefonica · Movistar 4G Router

Gabriel Gonzalez Garcia

·

Published

2024-03-13

·

Updated

2024-03-13

·

CVE-2024-2415

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Movistar 4G router version ES WLD71-T1 v2.0.201820
Description The issue is a command injection vulnerability that allows an authenticated user to execute commands inside the router. This can be achieved by making a POST request to the API endpoint '/cgi-bin/gui.cgi'.
Recommendations For version ES WLD71-T1 v2.0.201820, as a temporary workaround, consider restricting access to the '/cgi-bin/gui.cgi' API endpoint until a patch is available.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-2415

Affected Products

Movistar 4G Router