CVE-2024-23789: Command Injection
Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23789?
CVE-2024-23789 is classified as a high severity vulnerability due to its potential for unauthenticated command execution.
How do I fix CVE-2024-23789?
To mitigate CVE-2024-23789, update the Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 to version B0.1.9.2 or later.
What types of attacks can CVE-2024-23789 enable?
CVE-2024-23789 allows an attacker to execute arbitrary OS commands on the vulnerable Energy Management Controller.
Which products are affected by CVE-2024-23789?
CVE-2024-23789 affects the Energy Management Controller with Cloud Services models JH-RVB1 and JH-RV11, specifically versions B0.1.9.1 and earlier.
Is authentication required to exploit CVE-2024-23789?
No, CVE-2024-23789 can be exploited by unauthenticated attackers who are network-adjacent.