Vulnerability Description
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.
Related Weaknesses (CWE)
References
- https://github.com/jpylypiw/easywall
- https://jpylypiw.github.io/easywall/
- https://www.exploit-db.com/exploits/51856
- https://www.vulncheck.com/advisories/easywall-031-authentication-bypass-via-comm
FAQ
What is CVE-2024-58275?
CVE-2024-58275 is a documented vulnerability. Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell ...
How severe is CVE-2024-58275?
CVSS scoring is not yet available for CVE-2024-58275. Check NVD for updates.
Is there a patch for CVE-2024-58275?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.