Security Advisory

CVE-2024-2415

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-13 11:18:38
Last updated 2024-08-05 15:13:31
Assigner INCIBE
State PUBLISHED

Description

Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL /cgi-bin/gui.cgi.