Arbitrary Command Execution Vulnerability in MZK-MF300N Firmware
CVE-2024-30220
8.8HIGH
What is CVE-2024-30220?
The MZK-MF300N firmware contains a command injection vulnerability that permits network-adjacent attackers to execute arbitrary commands remotely. This occurs when specially crafted requests are sent to specific ports, enabling an attacker to compromise the device without the need for authentication. Users are advised to review their firmware versions and implement security measures to thwart potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MZK-MF300HP2 firmware versions 1.18 and earlier
MZK-MF300N all firmware versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
