PT-2024-39458 · Hms Networks · Ewon Flexy 205

·

CVE-2024-9154

·

Published

2024-12-19

·

Updated

2024-12-22

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ewon Flexy 205 versions through 14.8s0
Description A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device.
Recommendations For Ewon Flexy 205 versions through 14.8s0, update to a version later than 14.8s0 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9154

Affected Products

Ewon Flexy 205