CVE-2024-47133

HIGH EXPLOITED

I-O DATA DEVICE UD-LT1 and UD-LT1/EX <= 2.1.9 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-47133 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

References (2)

Core 2

Scores

CVSS v3 7.2
EPSS 0.0089
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2024-12-04
CWE
CWE-78
Status published
Products (2)
I-O DATA DEVICE, INC./UD-LT1 firmware Ver.2.1.9 and earlier
I-O DATA DEVICE, INC./UD-LT1/EX firmware Ver.2.1.9 and earlier
Published Dec 05, 2024
Tracked Since Feb 18, 2026