Rakuten Turbo 5G Firmware Vulnerability Could Allow Arbitrary OS Command Execution
CVE-2024-48895
8.8HIGH
What is CVE-2024-48895?
An OS command injection vulnerability exists in the firmware of Rakuten Turbo 5G, specifically in versions V1.3.18 and earlier. This flaw results from improper handling of special elements used in OS commands. If successfully exploited by a remote authenticated attacker, the vulnerability could lead to the execution of arbitrary OS commands on the affected system, potentially compromising the security integrity of the device and its data.
Affected Version(s)
Rakuten Turbo 5G V1.3.18 and earlier