CVE-2020-24552

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
10/09/2020
Last modified:
16/09/2020

Description

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:atoptechnology:se5901_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5901:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5901b_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5901b:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5904d_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5904d:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5908_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5908:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5908a_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5908a:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5916_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5916:-:*:*:*:*:*:*:*
cpe:2.3:o:atoptechnology:se5916a_firmware:*:*:*:*:*:*:*:* 1.18 (including) 1.40 (including)
cpe:2.3:h:atoptechnology:se5916a:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools