CVE-2024-4638

EUVD-2024-44242
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
moxaoncell_g3470a-lte-eu-t_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-eu_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-us_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-us-t_firmware
𝑥
≤ 1.7.7
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
moxaoncell_g3470a-lte-us
𝑥
≤ 1.7.7
ADP