CVE-2024-36439
published 2024-08-22CVE-2024-36439: Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without…
PriorityP267critical9.4CVSS 3.1
AVNACLPRNUINSUCHIHAL
EPSS
0.88%
54.6th percentile
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red/https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-038.txthttp://seclists.org/fulldisclosure/2024/Aug/32http://seclists.org/fulldisclosure/2024/Aug/39http://seclists.org/fulldisclosure/2024/Aug/40
2024-08-22
Published