Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/yckuo-sdc/PoC |
|
History
Tue, 25 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
4ipnet
4ipnet eap-767 4ipnet eap-767 Firmware |
|
| CPEs | cpe:2.3:h:4ipnet:eap-767:*:*:*:*:*:*:*:* cpe:2.3:o:4ipnet:eap-767_firmware:3.42.00:*:*:*:*:*:*:* |
|
| Vendors & Products |
4ipnet
4ipnet eap-767 4ipnet eap-767 Firmware |
Tue, 27 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-14T00:00:00
Updated: 2024-08-27T18:56:01.133Z
Reserved: 2024-01-25T00:00:00
Link: CVE-2024-24301
Updated: 2024-08-01T23:19:52.026Z
Status : Analyzed
Published: 2024-02-14T23:15:08.190
Modified: 2025-03-25T15:18:58.773
Link: CVE-2024-24301
No data.
ReportizFlow