PT-2025-49133 · Unknown · Radio Network Fm Transmitter

Published

2025-12-04

·

Updated

2025-12-04

·

CVE-2024-58277

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions R Radio Network FM Transmitter version 1.07
Description An unauthenticated attacker can access the admin user's password through the system.cgi endpoint. This allows for authentication bypass and access to FM station setup. The system.cgi API endpoint is vulnerable.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the system.cgi endpoint.

Exploit

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-58277

Affected Products

Radio Network Fm Transmitter