cbcvebase.
CVE-2024-50375
published 2024-11-26

CVE-2024-50375: A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3)…

PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.03%
59.3th percentile
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by remote unauthenticated users capable of interacting with the default "edgserver" service enabled on the access point.

Affected

6 ranges
VendorProductVersion rangeFixed in
advantecheki-6333ac-1gpo<= <= 1.2.1
advantecheki-6333ac-1gpo_firmware< 1.2.21.2.2
advantecheki-6333ac-2g<= <= 1.6.3
advantecheki-6333ac-2g_firmware< 1.6.51.6.5
advantecheki-6333ac-2gd<= <= 1.6.3
advantecheki-6333ac-2gd_firmware< 1.6.51.6.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.