Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52201 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input. |
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Victure
Victure rx1800 Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:victure:rx1800_firmware:en_v1.0.0_r12_110933:*:*:*:*:*:*:* | |
| Vendors & Products |
Victure
Victure rx1800 Firmware |
|
| Metrics |
cvssV3_1
|
Mon, 02 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-bin/luci/admin/opsw/Dual_freq_un_apple endpoint is vulnerable to command injection through the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute arbitrary commands on the device (with root-level permissions) via crafted input. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-03T18:54:24.260Z
Reserved: 2024-11-25T00:00:00.000Z
Link: CVE-2024-53939
Updated: 2024-12-03T18:54:13.835Z
Status : Deferred
Published: 2024-12-02T22:15:10.757
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-53939
No data.
OpenCVE Enrichment
No data.
EUVD