OS Command Injection Vulnerability in Newtec/iDirect Modems
CVE-2024-13502
9.3CRITICAL
What is CVE-2024-13502?
The vulnerability arises from improper parsing of incoming data on the commit_multicast
page within the modem's web administration interface. This flaw allows attackers to exploit the system by injecting arbitrary shell commands, potentially leading to unauthorized code execution. Specifically, the vulnerable script uses an eval
statement in a bash environment, posing significant security risks to the affected Newtec/iDirect modem models.
Affected Version(s)
NTC2218, NTC2250, NTC2299 Linux 1.0.1.1 <= 2.2.6.19