CVE-2024-29269

Published Apr 10, 2024

Last updated 9 months ago

CVSS high 8.8
Telesquare
TLR-2005Ksh

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-29269 is a command injection vulnerability affecting Telesquare TLR-2005Ksh devices, specifically versions 1.0.0 and 1.1.4. It allows attackers to execute arbitrary system commands remotely by exploiting the "Cmd" parameter. This vulnerability exists because the software constructs commands using external input without properly neutralizing special elements. An attacker can exploit this to gain unauthorized access and control of the affected system.

Description
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-77

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.