CVE-2024-28015OS Command Injection in Corporation Cr2500p

Severity
9.8CRITICALNVD
EPSS
0.8%
top 26.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28

Description

Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages58 packages

CVEListV5nec_corporation/wf300hp2all versions
CVEListV5nec_corporation/wg1810hpall versions
CVEListV5nec_corporation/wf1200hp2all versions
CVEListV5nec_corporation/wg1200hp2all versions
CVEListV5nec_corporation/wg1200hp3all versions

🔴Vulnerability Details

2
CVEList
CVE-2024-28015: Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, W2024-03-28
GHSA
GHSA-47wm-wmj9-988c: Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, W2024-03-28
CVE-2024-28015 — OS Command Injection | cvebase