PT-2024-35438 · Dcme-720+3 · Dcme-720+3
Published
2024-11-29
·
Updated
2024-12-04
·
CVE-2024-52781
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DCME-320 versions 7.4.12.90 and earlier
DCME-520 versions 9.25.5.11 and earlier
DCME-320-L versions 9.3.5.26 and earlier
DCME-720 versions 9.1.5.11 and earlier
Description
The issue allows for Remote Code Execution via the "/function/system/tool/traceroute.php" API endpoint. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations
For DCME-320 versions 7.4.12.90 and earlier, consider disabling access to the "/function/system/tool/traceroute.php" API endpoint until a patch is available.
For DCME-520 versions 9.25.5.11 and earlier, consider disabling access to the "/function/system/tool/traceroute.php" API endpoint until a patch is available.
For DCME-320-L versions 9.3.5.26 and earlier, consider disabling access to the "/function/system/tool/traceroute.php" API endpoint until a patch is available.
For DCME-720 versions 9.1.5.11 and earlier, consider disabling access to the "/function/system/tool/traceroute.php" API endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dcme-320
Dcme-320-L
Dcme-520
Dcme-720