CVE-2024-10119: SECOM WRTM326 - OS Command Injection
Published Oct 18, 2024
·Updated
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.
Affected Software
2 affected components
All of the following
ZTE Wrtm326 Firmware<=2.3.20
ZTE Wrtm326
Remediation
Information
Update WRTM326 to version 2.3.20 or later.
Event History
Oct 18, 2024
CVE Published
via MITRE·04:09 AM
Data Sourced
via MITRE·04:09 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10119?
CVE-2024-10119 has been assigned a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2024-10119?
To mitigate CVE-2024-10119, ensure that you update the WRTM326 firmware to the latest version above 2.3.20.
3
Who is affected by CVE-2024-10119?
Users of the SECOM WRTM326 wireless router with firmware version 2.3.20 or earlier are affected by CVE-2024-10119.
4
What types of attacks can be executed using CVE-2024-10119?
CVE-2024-10119 could allow unauthenticated attackers to execute arbitrary system commands remotely.
5
Is authentication required to exploit CVE-2024-10119?
No, CVE-2024-10119 can be exploited by unauthenticated remote attackers.