216.73.216.197

CVE-2024-28138

· Published 10/12/2024 08:15 · Modified 11/12/2024 17:15

Labels: CVE-2024-28138 2024-12-10551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2024-28138CWE-78

Essential information

Published
10/12/2024 08:15
Modified
11/12/2024 17:15
Author
Creator
CVSS
7.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

References