PT-2025-15386 · Senron · Senron 7Kt Pac1260 Data Manager

Published

2025-04-08

·

Updated

2025-04-08

·

CVE-2024-41788

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SENRON 7KT PAC1260 Data Manager (All versions)
Description: A vulnerability has been identified in the web interface of affected devices, where input parameters in specific GET requests are not sanitized. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.
Recommendations: Update the software to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation. Avoid using the vulnerable web interface until the issue is resolved.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-04011
CVE-2024-41788

Affected Products

Senron 7Kt Pac1260 Data Manager