Source: Ministry of education information & communication security contingency platform
Publication Number | TACERT-ANA-2024102101104848 | Publication Time | 2024/10/21 13:12 |
Incident Type | ANA-Vulnerability Alert | Discovery Time | 2024/10/19 13:12 |
Impact Level | Medium | ||
[Subject] 【Vulnerability Alert】Taiwan Secom WRTR-304GN-304TW-UPSC - OS Command Injection |
|||
[Content] Forwarded from TWCERTCC-200-202410-00000010 TWCERT/CC issued TVN-202410016, CVE-2024-10118 (CVSS: 9.8) on 2024-10-18. A specific feature in Taiwan Secom's WRTR-304GN-304TW-UPSC fails to properly filter user input, allowing remote attackers without authentication to exploit this vulnerability and inject arbitrary system commands, executing them on the device. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
[Affected Platform] WRTR-304GN-304TW-UPSC V02 |
|||
[Recommended Actions] The product is no longer maintained, and it is recommended to replace the equipment. |
|||
[Reference] Taiwan Secom WRTR-304GN-304TW-UPSC - OS Command Injection:https://www.twcert.org.tw/tw/cp-132-8154-69fa5-1.html |