Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 18 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sunniwell
Sunniwell ht3300 Firmware |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:o:sunniwell:ht3300_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sunniwell
Sunniwell ht3300 Firmware |
|
| Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to a command injection vulnerability, which could allow an attacker to pass commands to this program via command line arguments to gain elevated root privileges. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-18T14:43:39.165Z
Reserved: 2024-10-08T00:00:00.000Z
Link: CVE-2024-48073
Updated: 2024-11-18T14:41:42.762Z
Status : Deferred
Published: 2024-11-08T22:15:20.787
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-48073
No data.
OpenCVE Enrichment
No data.