PT-2024-27508 · Unknown · Cym1102 Nginxwebui

138Cym1102

·

Published

2024-04-13

·

Updated

2025-08-21

·

CVE-2024-3738

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cym1102 nginxWebUI versions up to 3.9.9
Description A critical vulnerability has been found in cym1102 nginxWebUI. This issue affects the handlePath function of the file /adminPage/conf/saveCmd. The manipulation of the nginxPath argument leads to improper certificate validation. It is possible to initiate the attack remotely.
Recommendations For cym1102 nginxWebUI versions up to 3.9.9, consider disabling the handlePath function until a patch is available. Restrict access to the /adminPage/conf/saveCmd file to minimize the risk of exploitation. Avoid using the nginxPath argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-3738

Affected Products

Cym1102 Nginxwebui