Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52798 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. |
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 31 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oringnet
Oringnet iap-420 Oringnet iap-420 Firmware |
|
| CPEs | cpe:2.3:h:oringnet:iap-420:-:*:*:*:*:*:*:* cpe:2.3:o:oringnet:iap-420_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oringnet
Oringnet iap-420 Oringnet iap-420 Firmware |
|
| Metrics |
cvssV3_1
|
Wed, 08 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 08 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | |
| Title | Authenticated Command Injection | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CyberDanube
Published:
Updated: 2025-11-03T22:32:32.429Z
Reserved: 2024-12-07T13:23:43.004Z
Link: CVE-2024-55544
Updated: 2024-12-10T19:53:36.924Z
Status : Modified
Published: 2024-12-10T16:15:24.107
Modified: 2025-11-03T23:17:29.603
Link: CVE-2024-55544
No data.
OpenCVE Enrichment
No data.
EUVD