CVE-2024-50960

HIGH

Extron SMP 111 <=3.01, SMP 351/352 <=2.16, SME 211 <=3.02 - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

Scores

CVSS v3 7.2
EPSS 0.0224
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (4)
extron/sme_211_firmware < 3.02
extron/smp_111_firmware < 3.01
extron/smp_351_firmware < 2.16
extron/smp_352_firmware < 2.16
Published Apr 15, 2025
Tracked Since Feb 18, 2026