PT-2024-35808 · Ae1021Pe+1 · Ae1021Pe+1
Chuya Hayakawa
+1
·
Published
2024-12-18
·
Updated
2024-12-23
·
CVE-2024-53688
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AE1021 firmware versions 2.0.10 and earlier
AE1021PE firmware versions 2.0.10 and earlier
Description
An issue exists due to the improper neutralization of special elements used in an OS command, which may allow a logged-in user to execute an arbitrary OS command using a crafted HTTP request. This issue is related to 'OS Command Injection'.
Recommendations
For AE1021 firmware versions 2.0.10 and earlier, consider disabling the ability to execute OS commands until a patch is available.
For AE1021PE firmware versions 2.0.10 and earlier, restrict access to the vulnerable module to minimize the risk of exploitation.
As a temporary workaround, avoid using crafted HTTP requests that may trigger the OS command injection issue until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ae1021
Ae1021Pe