CVE-2024-7066

HIGH

F-logic DataCube3 1.0 - OS Command Injection via ntp_server Argument

Title source: llm
STIX 2.1

Description

A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272347.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.272347
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.272347
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.378322

Scores

CVSS v3 7.3
EPSS 0.0337
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
f-logic/datacube3_firmware
Published Jul 24, 2024
Tracked Since Feb 18, 2026