PoC Index

CVE-2024-9166

CRITICAL 9.3EPSS 1.6%

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVSS v4.0
9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS
1.58% chance of exploitation in the next 30 days, 74th percentile
Nuclei
critical · CWE-78
Published
2024-09-26

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related