-2.9 C
Washington
Monday, February 3, 2025

Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation

Must read

Cybersecurity researchers have disclosed three safety flaws in Planet Expertise’s WGS-804HPT industrial switches that might be chained to realize pre-authentication distant code execution on prone gadgets.

“These switches are broadly utilized in constructing and residential automation programs for quite a lot of networking functions,” Claroty’s Tomer Goldschmidt mentioned in a Thursday report. “An attacker who is ready to remotely management one in every of these gadgets can use them to additional exploit gadgets in an inner community and do lateral motion.”

The operational expertise safety agency, which carried out an in depth evaluation of the firmware utilized in these switches utilizing the QEMU framework, mentioned the vulnerabilities are rooted within the dispatcher.cgi interface used to offer an internet service. The checklist of flaws is beneath –

  • CVE-2024-52558 (CVSS rating: 5.3) – An integer underflow flaw that may enable an unauthenticated attacker to ship a malformed HTTP request, leading to a crash
  • CVE-2024-52320 (CVSS rating: 9.8) – An working system command injection flaw that may enable an unauthenticated attacker to ship instructions by way of a malicious HTTP request, leading to distant code execution
  • CVE-2024-48871 (CVSS rating: 9.8) – A stack-based buffer overflow flaw that may enable an unauthenticated attacker to ship a malicious HTTP request, leading to distant code execution

Profitable exploitation of the issues might allow an attacker to hijack the execution circulation by embedding a shellcode within the HTTP request and achieve the power to execute working system instructions.

Following accountable disclosure, the Taiwanese firm has rolled out patches for the shortcomings with model 1.305b241111 launched on November 15, 2024.

See also  10 video games that are actually funny

Related News

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest News