nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-54006 CVE-2024-54006
HIGH
Authenticated Remote Command Injection Vulnerability in the Web Interface of a 501 Wireless Client Bridge
Record summary
CVE-2024-54006 has a selected CVSS score of 7.2 (high).
Description
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying operating system. Exploitation requires administrative authentication credentials on the host system.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
501 Wireless Client BridgeBrowse HPE Aruba Networking / 501 Wireless Client Bridge | VulnCheck | Version data not supplied | |
HPE Aruba Networking 501 Wireless Client BridgeBrowse Hewlett Packard Enterprise (HPE) / HPE Aruba Networking 501 Wireless Client BridgeDefault status: unaffected | CVE List | V2.0.0.0 to ≤ V2.1.1.0-B0030 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04763en_us&docLocale=en_US