I-O DATA DEVICE, INC. Vulnerabilities and Affected Products
Vulnerabilities associated with UD-LT1.
Products
Clear product- TS-PTCAM/POE4 vulnerabilities
- TS-WLC24 vulnerabilities
- TS-WLCE4 vulnerabilities
- TS-WPTCAM4 vulnerabilities
- TS-WPTCAM24 vulnerabilities
- TS-WRLC4 vulnerabilities
- UD-LT24 vulnerabilities
- Multiple I-O DATA network camera products3 vulnerabilities
- TS-WRLA3 vulnerabilities
- TS-WRLP3 vulnerabilities
- UD-LT13 vulnerabilities
- UD-LT1/EX3 vulnerabilities
- WN-AX1167GR3 vulnerabilities
- WN-G300R33 vulnerabilities
- HDL-T1NV2 vulnerabilities
- HDL-T1WH2 vulnerabilities
- HDL-T2NV2 vulnerabilities
- HDL-T2WH2 vulnerabilities
- HDL-T3NV2 vulnerabilities
- HDL-T3WH2 vulnerabilities
- HDL-TC12 vulnerabilities
- HDL-TC5002 vulnerabilities
- WFS-SR012 vulnerabilities
- WN-7D36QR2 vulnerabilities
- WN-7D36QR/UE2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-52564HIGH | UD-LT1 and UD-LT1/EX Firmware Arbitrary OS Command ExecutionInclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. CWE-1242Dec 5, 2024 | CVSS7.5v3.0 | EPSS0.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47133HIGH | UD-LT1 and UD-LT1/EX Firmware Admin Account Arbitrary OS Command ExecutionUD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands. CWE-78Dec 5, 2024 | CVSS7.2v3.0 | EPSS0.904% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-45841MEDIUM | UD-LT1 and UD-LT1/EX Firmware Guest Account Credential DisclosureIncorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained. CWE-732Dec 5, 2024 | CVSS6.5v3.0 | EPSS0.483% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |