CVE-2024-55514: Malicious File Upload
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /uploadsfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55514?
CVE-2024-55514 is classified as a critical vulnerability due to its ability to allow arbitrary file uploads leading to unauthorized access.
How do I fix CVE-2024-55514?
To mitigate CVE-2024-55514, ensure you update the firmware of affected Raisecom devices to the latest version provided by the vendor.
What are the affected products in CVE-2024-55514?
The affected products for CVE-2024-55514 include Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 devices.
What is the impact of exploiting CVE-2024-55514?
Exploiting CVE-2024-55514 can lead to unauthorized file uploads that may compromise server permissions and security.
Is there a way to detect exploitation of CVE-2024-55514?
Detecting exploitation of CVE-2024-55514 involves monitoring server logs for unusual file uploads or unauthorized access attempts.