PT-2024-39975 · Mitrastar · Mitrastar Gpt-2541Gnac

Peritocibernetico

·

Published

2024-10-15

·

Updated

2024-10-16

·

CVE-2024-9977

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MitraStar GPT-2541GNAC BR g5.6 1.11(WVK.0)b26
Description A critical issue was found in the Firewall Settings Page component, specifically in the /cgi-bin/settings-firewall.cgi file. The SrcInterface argument is vulnerable to os command injection, allowing for remote attacks. The issue has been publicly disclosed.
Recommendations For MitraStar GPT-2541GNAC BR g5.6 1.11(WVK.0)b26, consider restricting access to the /cgi-bin/settings-firewall.cgi file as a temporary workaround until a patch is available. Avoid manipulating the SrcInterface argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-9977

Affected Products

Mitrastar Gpt-2541Gnac