Authenticated OS Command Injection Vulnerability in MC LR Router 2.10.5
CVE-2024-28026

7.2HIGH

Key Information:

Vendor
CVE Published:
21 November 2024

What is CVE-2024-28026?

Three distinct OS command injection vulnerabilities have been identified within the web interface's I/O configuration capabilities of the MC Technologies MC LR Router, specifically in version 2.10.5. These vulnerabilities enable an attacker, upon authentication, to send a specially crafted HTTP request which can execute arbitrary commands on the device. The exploitation involves manipulating the 'out1' parameter in a way that allows the execution of commands through the system's shell, potentially compromising the integrity and security of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MC LR Router 2.10.5 (QEMU)

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.