CVE-2024-46330
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 78
Summary
CVE-2024-46330: A command injection vulnerability has been identified in VONETS VAP11G-300 v3.3.23.6.9. This issue lies in the iptablesWebsFilterRun object, allowing an attacker to inject and execute arbitrary commands on the affected system with potential privilege escalation. Successful exploitation could lead to significant security risks, including unauthorized access and data breaches. System administrators are strongly advised to update their VAP11G-300 devices to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.