File Creation Vulnerability in Pioneer DMH-WT7600NEX Devices
CVE-2024-23929

7.3HIGH

Key Information:

Vendor

Pioneer

Vendor
CVE Published:
31 January 2025

What is CVE-2024-23929?

A vulnerability exists in the telematics functionality of Pioneer DMH-WT7600NEX devices, allowing authenticated network-adjacent attackers to bypass the authentication mechanism. This flaw arises from improper validation of user-supplied paths before file operations, enabling attackers to create arbitrary files. Exploiting this vulnerability could lead to the execution of arbitrary code with root privileges when combined with other vulnerabilities. Securing the input validation process is essential to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DMH-WT7600NEX all versions

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.