PoC Index

CVE-2024-24301

HIGH 8.8EPSS 2.1%

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
2.10% chance of exploitation in the next 30 days, 80th percentile
Published
2024-02-14
Updated
2024-08-27

Proof-of-concept exploits (1)

References

Related