Vulnerability Description
Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU94872523/
- https://www.seiko-sol.co.jp/archives/82992/
- https://jvn.jp/en/vu/JVNVU94872523/
- https://www.seiko-sol.co.jp/archives/82992/
FAQ
What is CVE-2024-32850?
CVE-2024-32850 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 ...
How severe is CVE-2024-32850?
CVE-2024-32850 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-32850?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.