PT-2024-23733 · Huashi · Huashi Private Cloud Cdn Live Streaming Acceleration Server

Published

2024-03-29

·

Updated

2024-08-22

·

CVE-2024-31032

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport version 1.1.2
Description An issue in the Huashi Private Cloud CDN Live Streaming Acceleration Server allows a remote attacker to execute arbitrary code via the manager/ipping.php component. This enables the attacker to potentially gain control over the system, leading to unauthorized access and malicious activities.
Recommendations For Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport version 1.1.2, consider disabling the manager/ipping.php component as a temporary workaround until a patch is available. Restrict access to this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-31032

Affected Products

Huashi Private Cloud Cdn Live Streaming Acceleration Server