CVE-2024-50370

CRITICAL

Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Unauthenticated OS Command Injection via cfg_cmd_set_eth_conf

Title source: llm
STIX 2.1

Description

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point and malicious commands are executed with root privileges. No authentication is enabled on the service and the source of the vulnerability resides in processing code associated to the "cfg_cmd_set_eth_conf" operation.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0135
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
advantech/eki-6333ac-1gpo_firmware < 1.2.2
advantech/eki-6333ac-2g_firmware < 1.6.5
advantech/eki-6333ac-2gd_firmware < 1.6.5
Published Nov 26, 2024
Tracked Since Feb 18, 2026