OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
No history.
Information
Published : 2024-06-25 09:15
Updated : 2024-11-21 09:43
NVD link : CVE-2024-4638
Mitre link : CVE-2024-4638
CVE.ORG link : CVE-2024-4638
JSON object : View
Products Affected
moxa
- oncell_g3470a-lte-us-t_firmware
- oncell_g3470a-lte-us-t
- oncell_g3470a-lte-eu-t
- oncell_g3470a-lte-us_firmware
- oncell_g3470a-lte-us
- oncell_g3470a-lte-eu_firmware
- oncell_g3470a-lte-eu-t_firmware
- oncell_g3470a-lte-eu
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')