CVE-2024-3871

CRITICAL

Delta Electronics DVW-W02W2-E2 <2.5.2 - RCE

Title source: llm
STIX 2.1

Description

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.

References (1)

Core 1
Core References
Various Sources
https://onekey.com/

Scores

CVSS v3 9.8
EPSS 0.0281
EPSS Percentile 86.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-120 CWE-77
Status published
Products (1)
Deltra Electronics/DVW-W02W2-E2 < 2.5.2
Published Apr 16, 2024
Tracked Since Feb 18, 2026