CVE-2024-1015

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:se-elektronic:e-ddc3.3_firmware:03.07.03:*:*:*:*:*:*:*
cpe:2.3:h:se-elektronic:e-ddc3.3:-:*:*:*:*:*:*:*

History

20 Jul 2026, 14:16

Type Values Removed Values Added
Summary (en) Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device. (en) Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.
References
  • () https://www.se-elektronic.com/.well-known/csaf/advisories/2026/se-sa-2026_001.json -
  • () https://www.se-elektronic.com/psirt-cybersecurity/ -

03 Jan 2025, 19:15

Type Values Removed Values Added
First Time Se-elektronic e-ddc3.3 Firmware
CPE cpe:2.3:o:se-elektronicgmbh:e-ddc3.3_firmware:03.07.03:*:*:*:*:*:*:* cpe:2.3:o:se-elektronic:e-ddc3.3_firmware:03.07.03:*:*:*:*:*:*:*

26 Dec 2024, 14:47

Type Values Removed Values Added
First Time Se-elektronic
Se-elektronic e-ddc3.3
CPE cpe:2.3:h:se-elektronicgmbh:e-ddc3.3:-:*:*:*:*:*:*:* cpe:2.3:h:se-elektronic:e-ddc3.3:-:*:*:*:*:*:*:*

21 Nov 2024, 08:49

Type Values Removed Values Added
References () https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html - Third Party Advisory () https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html - Third Party Advisory
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-se-elektronic-gmbh-products - Third Party Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-se-elektronic-gmbh-products - Third Party Advisory

02 Feb 2024, 02:04

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-se-elektronic-gmbh-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-se-elektronic-gmbh-products - Third Party Advisory
References () https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html - () https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html - Third Party Advisory
CPE cpe:2.3:h:se-elektronicgmbh:e-ddc3.3:-:*:*:*:*:*:*:*
cpe:2.3:o:se-elektronicgmbh:e-ddc3.3_firmware:03.07.03:*:*:*:*:*:*:*
First Time Se-elektronicgmbh
Se-elektronicgmbh e-ddc3.3
Se-elektronicgmbh e-ddc3.3 Firmware
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

30 Jan 2024, 09:15

Type Values Removed Values Added
References
  • () https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html -

29 Jan 2024, 14:25

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-29 14:15

Updated : 2026-07-20 14:16


NVD link : CVE-2024-1015

Mitre link : CVE-2024-1015

CVE.ORG link : CVE-2024-1015


JSON object : View

Products Affected

se-elektronic

  • e-ddc3.3
  • e-ddc3.3_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')