CVE-2024-55544

Severity CVSS v4.0:
HIGH
Type:
CWE-77 Command Injection
Publication date:
10/12/2024
Last modified:
03/11/2025

Description

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:oringnet:iap-420_firmware:*:*:*:*:*:*:*:* 2.01e (including)
cpe:2.3:h:oringnet:iap-420:-:*:*:*:*:*:*:*