CVE-2024-55020 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 3, 2026
Weintek cMT-3072XH2 easyweb - Command Injection
Published: March 3, 2026Updated: March 3, 2026Remote Exploitable
Overview
Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 contains a command injection caused by improper input handling in DHCP activation feature, letting attackers execute arbitrary commands with root privileges, exploit requires network access.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute arbitrary commands with root privileges, leading to full system compromise.
Mitigation
Update to the latest version or apply vendor patches addressing this vulnerability.
References
Related Resources
Details
- CVE ID
- CVE-2024-55020
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- command_injection
- Status
- unconfirmed
CWE
- CWE-20
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H