CVE-2024-22813

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memory, disrupting network connectivity between the router and the controller.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:tormach:pathpilot_controller:2.9.6:*:*:*:*:*:*:*
cpe:2.3:h:tormach:xstech_cnc_router:-:*:*:*:*:*:*:*

History

15 Sep 2025, 16:18

Type Values Removed Values Added
CPE cpe:2.3:a:tormach:pathpilot_controller:2.9.6:*:*:*:*:*:*:*
cpe:2.3:h:tormach:xstech_cnc_router:-:*:*:*:*:*:*:*
First Time Tormach xstech Cnc Router
Tormach pathpilot Controller
Tormach
References () https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9 - () https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9 - Third Party Advisory

21 Nov 2024, 08:56

Type Values Removed Values Added
References () https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9 - () https://gist.github.com/VcuCyber/51075894d1728db07fc2df286c003df9 -

03 Jul 2024, 01:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4
Summary
  • (es) Un problema en Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 permite a los atacantes sobrescribir la dirección IP codificada en la memoria del dispositivo, interrumpiendo la conectividad de red entre el enrutador y el controlador.
CWE CWE-798

22 Apr 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-22 12:15

Updated : 2025-09-15 16:18


NVD link : CVE-2024-22813

Mitre link : CVE-2024-22813

CVE.ORG link : CVE-2024-22813


JSON object : View

Products Affected

tormach

  • pathpilot_controller
  • xstech_cnc_router
CWE
CWE-798

Use of Hard-coded Credentials