CVE-2024-50695

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 24, 2025
Updated: Feb 5, 2025
CWE ID 121

Summary

CVE-2024-50695 is a newly disclosed vulnerability affecting SunGrow WiNet-SV200.001.00.P027 and older versions. The issue stems from an absence of bounds checks on MQTT (Message Queuing Telemetry Transport) topics, leading to a stack-based buffer overflow. Successful exploitation of this vulnerability may result in code injection and subsequent unauthorized control over affected systems. This weakness could potentially allow attackers to execute arbitrary commands or gain elevated privileges. It is recommended that users update their SunGrow WiNet firmware to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share