CVE-2024-28138
10.12.2024, 08:15
An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user.The HTTP GET parameter "data" is not properly sanitized.
Awaiting analysis
This vulnerability is currently awaiting analysis.