Record summary

CVE-2024-45827 has a selected CVSS score of 8.0 (high); EIP currently links 1 repository PoC.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may execute an arbitrary OS command.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE Listfirmware version v1.0.2 and earlieraffected

Default status: unknown

CVE ListThrough 1.0.2affected

Proofs of concept

1

Repository PoCs

GitHub0xNslabs/CVE-2024-45827-PoCRepository PoCby 0xNslabsStars: 0Not analyzed6 files

13.8 KiB

GitHub

PoC details

References

2