CVE-2024-41153

HIGH

Hitachi Energy TRO600 Series Firmware 9.1.0.0-9.2.0.5 - Authenticated OS Command Injection via Edge Computing UI

Title source: llm
STIX 2.1

Description

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive than what the write privilege intends.

Scores

CVSS v3 7.2
EPSS 0.0156
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-78
Status published
Products (3)
hitachienergy/tro610_firmware 9.1.0.0 - 9.2.0.5
hitachienergy/tro620_firmware 9.1.0.0 - 9.2.0.5
hitachienergy/tro670_firmware 9.1.0.0 - 9.2.0.5
Published Oct 29, 2024
Tracked Since Feb 18, 2026