Command Injection Vulnerability in Vivotek SD9364 Product
CVE-2024-7442
9.8CRITICAL
What is CVE-2024-7442?
A significant command injection vulnerability has been identified in Vivotek's SD9364 product, particularly in the file management function āupload_file.cgiā. By manipulating the QUERY_STRING argument, an attacker can execute arbitrary commands on the affected system remotely. This vulnerability is especially concerning as it impacts a product that is no longer supported by Vivotek, highlighting the risks associated with utilizing outdated technology. Users are strongly advised to discontinue use of this product or seek alternative solutions to mitigate the risk of remote exploitation.
Affected Version(s)
SD9364 VVTK-0103f