CVE-2024-24301

HIGH

4ipnet EAP-767 Firmware 3.42.00 - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.

References (1)

Core 1
Core References
Exploit, Mitigation, Third Party Advisory
https://github.com/yckuo-sdc/PoC

Scores

CVSS v3 8.8
EPSS 0.0210
EPSS Percentile 79.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
4ipnet/eap-767_firmware 3.42.00
Published Feb 14, 2024
Tracked Since Feb 18, 2026