Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.
History

Thu, 26 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Gigastone
Gigastone travel Router R101 Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:gigastone:travel_router_r101_firmware:1.0.2:*:*:*:*:*:*:*
Vendors & Products Gigastone
Gigastone travel Router R101 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Description Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-25T00:00:00

Updated: 2024-09-26T14:09:19.811Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44678

cve-icon Vulnrichment

Updated: 2024-09-26T13:57:18.052Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T17:15:18.990

Modified: 2024-09-26T14:35:14.687

Link: CVE-2024-44678

cve-icon Redhat

No data.