Exploitation Summary
CVE-2024-5421 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
Nuclei Templates (1)
SEH utnserver Pro/ProMAX/INU-100 20.1.22 - File Exposure
HIGHVERIFIEDby bl4ckp4r4d1s3
Shodan:
SEH HTTP Server
References (2)
Core 2
Core References
Various Sources
https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html
Mailing List
http://seclists.org/fulldisclosure/2024/Jun/4
Scores
CVSS v4
8.7
EPSS
0.0369
EPSS Percentile
88.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (3)
SEH Computertechnik/INU-100
< 20.1.22
SEH Computertechnik/utnserver Pro
< 20.1.22
SEH Computertechnik/utnserver ProMAX
< 20.1.22
Published
Jun 04, 2024
Tracked Since
Feb 18, 2026