CVE-2024-4232

MEDIUM

Digisol Router <3.2.02 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-4232. PoCs published by Redfox-Security.

AI-analyzed exploit summary The repository contains only a README file with minimal content, lacking any exploit code or technical details about CVE-2024-4232. It appears to be a placeholder without functional or analytical content.

Description

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.

Exploits (2)

nomisec STUB
by Redfox-Security · poc
https://github.com/Redfox-Security/Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232

The repository contains only a README file with minimal content, lacking any exploit code or technical details about CVE-2024-4232. It appears to be a placeholder without functional or analytical content.

Classification
Stub 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Digisol DG-GR1321
No auth needed
Prerequisites: Access to the device's configuration or storage where passwords are stored in plaintext
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB
by Redfox-Security · poc
https://github.com/Redfox-Security/Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232

The repository contains only a README file with minimal content, lacking any exploit code or technical details about CVE-2024-4232. It appears to be a placeholder without substantive information.

Classification
Stub 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Digisol DG-GR1321
No auth needed
Prerequisites: Access to the device's configuration or storage where passwords are stored in plaintext
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 4.1
EPSS 0.0034
EPSS Percentile 25.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-256
Status published
Products (1)
Digisol/Digisol Router DG-GR1321 v3.2.02
Published May 14, 2024
Tracked Since Feb 18, 2026