cbcvebase.
CVE-2024-50376
published 2024-11-26

CVE-2024-50376: A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by…

PriorityP422medium5.2CVSS 3.1
AVAACLPRNUIRSCCLILAN
EPSS
0.45%
36.1th percentile
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

Affected

6 ranges
VendorProductVersion rangeFixed in
advantecheki-6333ac-1gpo<= <= 1.2.1
advantecheki-6333ac-1gpo_firmware< 1.2.21.2.2
advantecheki-6333ac-2g<= <= 1.6.3
advantecheki-6333ac-2g_firmware< 1.6.51.6.5
advantecheki-6333ac-2gd<= <= 1.6.3
advantecheki-6333ac-2gd_firmware< 1.6.51.6.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.