PT-2025-49133 · Unknown · Radio Network Fm Transmitter

CVE-2024-58277

·

Published

2025-12-04

·

Updated

2025-12-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions R Radio Network FM Transmitter version 1.07
Description An unauthenticated attacker can access the admin user's password through the system.cgi endpoint. This allows for authentication bypass and access to FM station setup. The system.cgi API endpoint is vulnerable.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the system.cgi endpoint.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58277

Affected Products

Radio Network Fm Transmitter