CVE-2024-24301

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.
References
Link Resource
https://github.com/yckuo-sdc/PoC Exploit Mitigation Third Party Advisory
https://github.com/yckuo-sdc/PoC Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:4ipnet:eap-767_firmware:3.42.00:*:*:*:*:*:*:*
cpe:2.3:h:4ipnet:eap-767:*:*:*:*:*:*:*:*

History

25 Mar 2025, 15:18

Type Values Removed Values Added
References () https://github.com/yckuo-sdc/PoCĀ - () https://github.com/yckuo-sdc/PoCĀ - Exploit, Mitigation, Third Party Advisory
First Time 4ipnet
4ipnet eap-767
4ipnet eap-767 Firmware
CPE cpe:2.3:o:4ipnet:eap-767_firmware:3.42.00:*:*:*:*:*:*:*
cpe:2.3:h:4ipnet:eap-767:*:*:*:*:*:*:*:*

Information

Published : 2024-02-14 23:15

Updated : 2025-03-25 15:18


NVD link : CVE-2024-24301

Mitre link : CVE-2024-24301

CVE.ORG link : CVE-2024-24301


JSON object : View

Products Affected

4ipnet

  • eap-767_firmware
  • eap-767
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')