PT-2024-31529 · Helmholz+1 · Rex100+3

Moritz Abrell

+1

·

Published

2024-10-14

·

Updated

2024-10-23

·

CVE-2024-45274

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. This issue allows a remote attacker to run OS commands through UDP without needing authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-45274

Affected Products

Rex100
Mbnet.Mini
Mbnet.Mini Firmware
Rex 100 Firmware