CVE-2024-58275
HIGHEasywall 0.3.1 - Authenticated Remote Command Execution via Ports-Save Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-58275. PoCs published by Melvin Mejia.
AI-analyzed exploit summary This exploit demonstrates an authenticated remote command execution vulnerability in Easywall 0.3.1. It leverages a command injection flaw in the 'port' parameter to execute a reverse shell via netcat.
Description
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.
Exploits (1)
This exploit demonstrates an authenticated remote command execution vulnerability in Easywall 0.3.1. It leverages a command injection flaw in the 'port' parameter to execute a reverse shell via netcat.
References (4)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N