First published: Wed Jul 24 2024(Updated: )
A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272347.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
F-logic Datacube3 Firmware | ||
F-logic Datacube3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7066 has been declared as critical.
To fix CVE-2024-7066, ensure that the ntp_server argument in /admin/config_time_sync.php is properly secured and validated.
CVE-2024-7066 affects the HTTP POST Request Handler of the component located at /admin/config_time_sync.php.
CVE-2024-7066 affects F-logic DataCube3 firmware version 1.0.
CVE-2024-7066 is a critical vulnerability involving OS command injection due to improper handling of the ntp_server argument.