Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-44610. PoCs published by BertoldVdb.
AI-analyzed exploit summary This repository contains a functional Go-based exploit for CVE-2024-44610, targeting PEAK PCAN-Ethernet Gateway FD DR devices. It chains two command injection vulnerabilities to achieve authenticated root RCE via a bindshell.
Description
PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.
Exploits (1)
This repository contains a functional Go-based exploit for CVE-2024-44610, targeting PEAK PCAN-Ethernet Gateway FD DR devices. It chains two command injection vulnerabilities to achieve authenticated root RCE via a bindshell.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L