CVE-2024-55515

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:raisecom:msg2300_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:raisecom:msg2100e_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2100e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:raisecom:msg2200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:raisecom:msg1200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg1200:-:*:*:*:*:*:*:*

History

28 Apr 2025, 17:13

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Raisecom MSG1200, MSG2100E, MSG2200 y MSG2300 3.90. El componente afectado por este problema es /upload_ipslib.php en la interfaz web. Al manipular un nombre de formulario adecuado, se pueden cargar archivos arbitrarios.
First Time Raisecom msg2200 Firmware
Raisecom msg2300 Firmware
Raisecom msg2200
Raisecom msg2100e Firmware
Raisecom msg1200 Firmware
Raisecom msg2300
Raisecom msg2100e
Raisecom msg1200
Raisecom
CPE cpe:2.3:o:raisecom:msg2100e_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg1200:-:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2300:-:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg2300_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg1200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg2200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2200:-:*:*:*:*:*:*:*
References () https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060 - () https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060 - Third Party Advisory

18 Dec 2024, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-22

17 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-17 20:15

Updated : 2025-04-28 17:13


NVD link : CVE-2024-55515

Mitre link : CVE-2024-55515

CVE.ORG link : CVE-2024-55515


JSON object : View

Products Affected

raisecom

  • msg2200_firmware
  • msg2200
  • msg1200
  • msg2100e_firmware
  • msg2300
  • msg1200_firmware
  • msg2100e
  • msg2300_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')