CVE-2024-53688

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to execute an arbitrary OS command using a crafted HTTP request.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Existe un problema de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comando del sistema operativo') en las versiones de firmware AE1021 2.0.10 y anteriores y en las versiones de firmware AE1021PE 2.0.10 y anteriores, lo que puede permitir que un usuario conectado ejecute un comando del sistema operativo arbitrario mediante una solicitud HTTP manipulada.

18 Dec 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-18 07:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-53688

Mitre link : CVE-2024-53688

CVE.ORG link : CVE-2024-53688


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')