CVE-2024-9977
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-9977 is a newly disclosed critical vulnerability affecting the MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26 Firewall Settings Page. The issue lies within an unknown function of the /cgi-bin/settings-firewall.cgi file, where manipulation of the argument SrcInterface allows for os command injection. This vulnerability can be exploited remotely, allowing attackers to execute arbitrary commands on the targeted system. The exploit has been made public, and efforts to contact the vendor for a patch have been unsuccessful as their official mail address seems to be inactive.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.