First published: Tue Dec 17 2024(Updated: )
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Raisecom Msg1200 Firmware | ||
Raisecom Msg2100e Firmware | ||
Raisecom Msg2200 Firmware | ||
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2300 | =3.90 | |
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2100e Firmware | =3.90 | |
Raisecom Msg2100e Firmware | ||
All of | ||
Raisecom Msg2200 | =3.90 | |
Raisecom Msg2200 Firmware | ||
All of | ||
Raisecom Msg1200 Firmware | =3.90 | |
Raisecom Msg1200 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55516 is considered a high severity vulnerability due to its potential for arbitrary file uploads and unauthorized access.
To fix CVE-2024-55516, you should update to the latest firmware version provided by Raisecom for affected devices.
CVE-2024-55516 impacts Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 devices running firmware version 3.90.
CVE-2024-55516 facilitates unauthorized file uploads, which can lead to various forms of exploitation including remote code execution.
You can determine if your device is vulnerable to CVE-2024-55516 by checking if it is running Raisecom firmware version 3.90.