CVE-2024-10771

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/12/2024
Last modified:
06/12/2024

Description

Due to missing input validation during one step of the firmware update process, the product<br /> is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker<br /> can execute arbitrary system commands in the root user’s contexts.