S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Aug 25, 2024

CVE-2024-7120 Scanner

CVE-2024-7120 scanner - Command Injection vulnerability in Raisecom MSG1200, MSG2100E, MSG2200, MSG2300

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7120
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
MSG1200by Raisecom
3.90
MSG2100Eby Raisecom
3.90
MSG2200by Raisecom
3.90
MSG2300by Raisecom
3.90
Updated Sep 10, 2026View on NVD →
Detail

Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 are network gateway devices commonly used in enterprise environments. They provide connectivity and management features essential for maintaining network infrastructure. These devices are widely deployed in settings where reliable network communication is critical. Their web-based interface allows for easy configuration and management. However, vulnerabilities within this interface can lead to significant security risks.

The Command Injection vulnerability in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 allows attackers to execute arbitrary commands on the device. This vulnerability is found in the web interface, specifically in the handling of user inputs in the list_base_config.php file. Exploitation of this flaw could allow unauthorized users to compromise the device remotely. This issue has been classified as critical and can be exploited without user interaction.

The vulnerability exists in the list_base_config.php file of the web interface, where the template parameter is not properly sanitized. An attacker can inject OS commands by manipulating this parameter, leading to remote command execution. This allows attackers to execute commands on the server with the same privileges as the web server. The issue can be triggered by sending a specially crafted HTTP request to the vulnerable endpoint, resulting in the execution of arbitrary code on the device.

Exploiting this vulnerability could allow attackers to gain unauthorized access to the device, execute arbitrary commands, and potentially take full control of the network gateway. This could lead to data breaches, network disruptions, and further exploitation of the internal network. The impact of this vulnerability is severe, as it could compromise the integrity and security of the entire network infrastructure managed by the affected devices.

By using the security scanning services provided by the S4E platform, you can proactively identify and remediate critical vulnerabilities like Command Injection in your network devices. The platform offers detailed reports and actionable insights, helping you to secure your infrastructure and prevent potential breaches. Join our platform to leverage comprehensive security checks and keep your systems protected from emerging threats.

References:

Solution Advice
  • Update the firmware to the latest version provided by the vendor.
  • Implement input validation on user inputs to prevent command injection.
  • Restrict access to the web interface to trusted IP addresses only.
  • Regularly monitor and audit the device's security settings and logs.
  • Apply security patches as soon as they become available from the vendor.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-7120 scanner - Command Injection vulnerability in Raisecom MSG1200, MSG2100E, MSG2200, MSG2300 | S4E