cbcvebase.
CVE-2024-4638
published 2024-06-25

CVE-2024-4638: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.

Affected

5 ranges
VendorProductVersion rangeFixed in
moxaoncell_g3470a-lte-eu-t_firmware<= 1.7.7
moxaoncell_g3470a-lte-eu_firmware<= 1.7.7
moxaoncell_g3470a-lte-us-t_firmware<= 1.7.7
moxaoncell_g3470a-lte-us_firmware<= 1.7.7
moxaoncell_g3470a-lte_series1.0 – 1.7.7