CVE-2024-22729
CRITICAL EXPLOITED NUCLEINetis MW5360 V1.0.1.3031 - Command Injection
Title source: nucleiExploitation Summary
CVE-2024-22729 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit, including a Metasploit module exploits/linux/http/netis_unauth_rce_cve_2024_22729.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in Netis MW5360 routers via the password parameter on the login page. The exploit uses base64-encoded commands to achieve remote code execution.
Description
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
Exploits (1)
This Metasploit module exploits an unauthenticated command injection vulnerability in Netis MW5360 routers via the password parameter on the login page. The exploit uses base64-encoded commands to achieve remote code execution.
Nuclei Templates (1)
title:"netis router"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H