Improper Neutralization of Special Elements in OS Commands Affects Advantech Devices
CVE-2024-50368
What is CVE-2024-50368?
An OS command injection vulnerability has been identified in multiple Advantech EKI devices, resulting from inadequate sanitization of parameters in the 'basic_htm' API. This oversight allows attackers to manipulate OS-level commands through specially crafted input. Affected devices include EKI-6333AC-2G, EKI-6333AC-2GD, and EKI-6333AC-1GPO, specifically versions less than or equal to 1.6.3 for the first two and less than or equal to 1.2.1 for the latter. Exploitation of this vulnerability enables malicious actors to execute arbitrary commands, potentially leading to unauthorized access and control over the vulnerable devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EKI-6333AC-1GPO 0
EKI-6333AC-2G 0
EKI-6333AC-2GD 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
