CVE-2024-38944
CRITICALIntelight X-1L Traffic controller Maxtime <1.9.6 - RCE
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-38944. PoCs published by Andrew Lemon/Red Threat.
AI-analyzed exploit summary This writeup describes an authentication bypass vulnerability in Intelight X-1L Traffic Controller's MaxTime Database Editor (version 1.9.x). The flaw allows unauthenticated access to the web-based UI via a specific CGI endpoint, enabling attackers to disable security settings or extract credentials.
Description
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.
Exploits (1)
This writeup describes an authentication bypass vulnerability in Intelight X-1L Traffic Controller's MaxTime Database Editor (version 1.9.x). The flaw allows unauthenticated access to the web-based UI via a specific CGI endpoint, enabling attackers to disable security settings or extract credentials.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H