Логотип exploitDog
bind:CVE-2024-58314
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-58314

Количество 2

Количество 2

nvd логотип

CVE-2024-58314

около 2 месяцев назад

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-94jm-p5xh-jj8r

около 2 месяцев назад

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-58314

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-94jm-p5xh-jj8r

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу