PT-2024-24079 · Roblox · Redon Hub
Pulse-Design
·
Published
2024-04-08
·
Updated
2026-01-07
·
CVE-2024-31442
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Redon Hub versions prior to 1.0.2
Description
The issue affects Redon Hub, a Roblox Product Delivery Bot. In affected versions, all commands can be executed by all users, including admin commands. This allows users to receive products for free and perform actions such as deleting, creating, or updating products, tags, etc. The only command that is not affected is
/products admin clear, as it was already restricted to bot owners. Users can upgrade to version 1.0.2 to receive a patch.Recommendations
For versions prior to 1.0.2, upgrade to version 1.0.2 to receive a patch. As a temporary workaround, consider restricting access to admin commands until the patch is applied. Avoid using vulnerable commands, except for the
/products admin clear command, which is already secure.Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redon Hub