CVE-2024-54007

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 77

Summary

CVE-2024-54007 is a newly identified vulnerability affecting the web interface of the 501 Wireless Client Bridge. This issue involves multiple command injection flaws that can be exploited by authenticated attackers to execute arbitrary commands on the underlying operating system with privileged user access. Successfully exploiting these vulnerabilities requires administrative authentication credentials on the host system, posing a significant security risk. Unauthorized command execution can lead to serious consequences, such as data theft, system damage, or unauthorized access to sensitive information. Users are urged to apply the necessary patches as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share