Description
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| oncell-g3470a-lte-eu-firmware | — | 1.7.7 |
| oncell-g3470a-lte-eu-t-firmware | — | 1.7.7 |
| oncell-g3470a-lte-us-firmware | — | 1.7.7 |
| oncell-g3470a-lte-us-t-firmware | — | 1.7.7 |
Similar Threats
- High CVE-2024-4639
- High CVE-2024-4640
- Medium CVE-2024-4641
Exploit Protection
Help block exploit attempts
BotEraser is designed to detect and help reduce malicious bot traffic that may target known vulnerabilities on your site.
Try BotEraser Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.