Advantech Devices Vulnerable to OS Command Injection
CVE-2024-50371
What is CVE-2024-50371?
A vulnerability has been identified that permits OS Command Injection in specific Advantech networking devices. This issue arises from improper neutralization of special elements, allowing remote unauthenticated users to exploit the default 'edgserver' service. The vulnerability enables attackers to execute malicious commands with root privileges, significantly compromising the security of the devices. The flaw is attributed to improper handling of code related to the 'wlan_scan' operation, which allows unauthorized access without any authentication mechanisms in place.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EKI-6333AC-1GPO 0
EKI-6333AC-2G 0
EKI-6333AC-2GD 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
