Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/CurryRaid/iot_vul/tree/main/comfast |
|
Fri, 13 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comfast cf-xr11
|
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:h:comfast:cf-xr11:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfast cf-xr11
|
Wed, 11 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comfast
Comfast cf-xr11 Firmware |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:o:comfast:cf-xr11_firmware:2.7.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Comfast
Comfast cf-xr11 Firmware |
|
| Metrics |
cvssV3_1
|
Wed, 11 Sep 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-11T17:33:25.923Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44466
Updated: 2024-09-11T17:33:19.696Z
Status : Analyzed
Published: 2024-09-11T16:15:06.330
Modified: 2024-09-13T16:32:15.977
Link: CVE-2024-44466
No data.
OpenCVE Enrichment
No data.