CVE-2024-23929

CVSS 3.1 Score 8 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 94

Summary

CVE-2024-23929 is a vulnerability affecting Pioneer DMH-WT7600NEX devices. It allows network-adjacent attackers to create arbitrary files by exploiting a flaw in the telematics functionality. Authentication is required to exploit this vulnerability, but the existing authentication mechanism can be bypassed. The root cause is a lack of proper validation of user-supplied paths before using them in file operations. An attacker can use this vulnerability in conjunction with others to execute arbitrary code with root privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share