CVE-2024-55514

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 17, 2024
Updated: Dec 18, 2024
CWE ID 434

Summary

CVE-2024-55514 is a newlydiscovered vulnerability affecting Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90 devices. The vulnerability lies in the /upload_sfmig.php file on the web interface. An attacker can exploit this flaw by submitting a specially crafted form name, enabling them to upload arbitrary files. Successful exploitation might grant unauthorized access to server permissions. Users are advised to apply patches or updates as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MSG2200
  • MSG1200
  • MSG2300
  • MSG2100E

Affected Vendors

  • Raisecom Technology Co.,Ltd.