CVE-2024-9166

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-09-26 17:15

Updated : 2024-09-30 12:46


NVD link : CVE-2024-9166

Mitre link : CVE-2024-9166

CVE.ORG link : CVE-2024-9166


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')