CVE-2024-5411

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
28/05/2024
Last modified:
29/10/2025

Description

Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:oringnet:iap-420_firmware:*:*:*:*:*:*:*:* 2.01e (including)
cpe:2.3:h:oringnet:iap-420:-:*:*:*:*:*:*:*