CVE-2024-4638: OnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKey
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OnCell G3470A-LTE Series firmwareto a version that resolves this vulnerability.Fixed in v1.7.8
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4638?
CVE-2024-4638 has a critical severity due to its potential for command injection vulnerabilities.
How do I fix CVE-2024-4638?
To remediate CVE-2024-4638, upgrade the firmware of the Moxa Oncell G3470A-LTE Series to a version later than v1.7.7.
What types of devices are affected by CVE-2024-4638?
CVE-2024-4638 impacts Moxa Oncell G3470A-LTE Series devices with firmware versions v1.7.7 and earlier.
What could an attacker do by exploiting CVE-2024-4638?
An attacker exploiting CVE-2024-4638 could execute unauthorized commands on the affected device, compromising its integrity.
Is there any mitigation for CVE-2024-4638 besides upgrading?
Currently, there are no alternative mitigations for CVE-2024-4638; upgrading to the latest firmware is strongly recommended.