CVE-2024-38944

CRITICAL

Intelight X-1L Traffic controller Maxtime <1.9.6 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-38944. PoCs published by Andrew Lemon/Red Threat.

AI-analyzed exploit summary This writeup describes an authentication bypass vulnerability in Intelight X-1L Traffic Controller's MaxTime Database Editor (version 1.9.x). The flaw allows unauthenticated access to the web-based UI via a specific CGI endpoint, enabling attackers to disable security settings or extract credentials.

Description

An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.

Exploits (1)

exploitdb WRITEUP
by Andrew Lemon/Red Threat · textwebappsmultiple
https://www.exploit-db.com/exploits/52151

This writeup describes an authentication bypass vulnerability in Intelight X-1L Traffic Controller's MaxTime Database Editor (version 1.9.x). The flaw allows unauthenticated access to the web-based UI via a specific CGI endpoint, enabling attackers to disable security settings or extract credentials.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Intelight X-1L Traffic Controller MaxTime Database Editor 1.9.x
No auth needed
Prerequisites: Network access to the target device · Knowledge of the target IP address
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.1215
EPSS Percentile 94.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Published Jul 22, 2024
Tracked Since Feb 18, 2026