S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-2621 Scanner

CVE-2024-2621 Scanner - Command Injection vulnerability in Fujian Kelixin Communication Command and Dispatch Platform

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2621
9.8
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php. The manipulation of the argument uuid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257198 is the identifier assigned to this vulnerability.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Command and Dispatch Platformby Fujian Kelixin Communication
20240318
Updated Aug 22, 2026View on NVD →
Detail

Fujian Kelixin Communication Command and Dispatch Platform is a versatile communication platform employed by organizations for structured internal command and dispatch operations. Primarily used in environments requiring robust and efficient communication channels, it facilitates user account management and permissions update through structured APIs. With a focus on delivering high performance and reliability, the platform supports real-time data exchanges crucial for operational tasks. The deployment of this platform is common across sectors needing streamlined dispatch services like emergency management services and large-scale industrial operations. It leverages cutting-edge technology to enhance intra-organizational communication efficiency while maintaining high security standards. The platform's scalability suits diverse organizational sizes and its up-to-date system architecture allows easy adaptability to emerging communication needs.

The Command Injection vulnerability detected in Fujian Kelixin Communication Command and Dispatch Platform allows unauthorized command execution by manipulating user input into scripts or system commands. This type of vulnerability can lead to severe security breaches as attackers could potentially execute arbitrary commands on the host system. Such vulnerabilities typically arise due to improper validation of user inputs within the application's functionalities. By compromising the platform's command execution procedures, malicious entities can undermine system integrity and confidentiality. Exploitation of this vulnerability provides backdoor access enabling attackers to execute system-level commands without legitimate permissions. Mitigating this vulnerability involves implementing rigorous input validation mechanisms to prevent command injection attacks effectively.

Technical details indicate that the vulnerability lies within the file api/client/user/pwd_update.php, where unsanitized inputs are processed. Attackers can inject malicious commands into parameters like usr_number in HTTP requests to exploit this vulnerability. The parameter is part of an endpoint responsible for password update operations, which lacks proper input sanitization. This endpoint, when misused, can trigger time-based command injection attacks, confirming vulnerability exploitation through response delays. Leveraging sleep commands to validate the execution of injected commands exemplifies the delicate nature of the flaw. The combination of certain HTTP status codes with specific response body contents can confirm successful exploitation and potential system access.

When exploited, this Command Injection vulnerability can allow attackers to execute arbitrary commands on the affected server, jeopardizing system integrity and data confidentiality. Attackers may leverage the vulnerability to gain unauthorized access, leading to data breaches and potential denial of service conditions. Exploitation might enable attackers to manipulate dispatch operations, causing operational disruptions. System compromises due to this vulnerability can also lead to sensitive information disclosure or unauthorized data modification. Furthermore, the possibility of establishing persistent control on the server increases the risk of long-term system abuse by attackers. Swift remediation is essential to safeguard against potential exploitation impacts.

REFERENCES

Solution Advice
  • Implement strict input validation on all API parameters to mitigate command injection risks.
  • Employ input sanitization libraries or frameworks to encode user inputs before processing.
  • Restrict application permissions to execute commands only from authenticated and authorized sources.
  • Regularly update and patch systems to protect against known vulnerabilities including command injection.
  • Conduct security assessments to uncover and fix potential exploitable points within the application infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-2621 Scanner - Command Injection vulnerability in Fujian Kelixin Communication Command and Dispatch Platform S4E