CVE-2024-10381

CRITICAL

Matrix Door Controller Cosec Vega FAXQ - RCE

Title source: llm
STIX 2.1

Description

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this vulnerability could allow remote attacker to gain unauthorized access and take complete control of the targeted device.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0083
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
matrixcomsec/cosec_vega_faxq_firmware < v2r17
Published Oct 25, 2024
Tracked Since Feb 18, 2026