CVE-2023-24837

HIGH

HGiga PowerStation - Command Injection

Title source: llm
STIX 2.1

Description

HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0093
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
hgiga/powerstation_firmware < x64.6.2.165
Published Mar 27, 2023
Tracked Since Feb 18, 2026