• About
  • Disclaimer
  • Privacy Policy
  • Contact
Sunday, June 15, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

Vital Flaws in WGS-804HPT Switches Allow RCE and Community Exploitation

Md Sazzad Hossain by Md Sazzad Hossain
0
Vital Flaws in WGS-804HPT Switches Allow RCE and Community Exploitation
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Jan 17, 2025Ravie LakshmananFirmware Safety / Vulnerability

Cybersecurity researchers have disclosed three safety flaws in Planet Know-how’s WGS-804HPT industrial switches that may very well be chained to realize pre-authentication distant code execution on vulnerable units.

“These switches are broadly utilized in constructing and residential automation techniques for a wide range of networking functions,” Claroty’s Tomer Goldschmidt mentioned in a Thursday report. “An attacker who is ready to remotely management considered one of these units can use them to additional exploit units in an inner community and do lateral motion.”

Cybersecurity

The operational know-how safety agency, which carried out an in depth evaluation of the firmware utilized in these switches utilizing the QEMU framework, mentioned the vulnerabilities are rooted within the dispatcher.cgi interface used to supply an internet service. The listing of flaws is beneath –

  • CVE-2024-52558 (CVSS rating: 5.3) – An integer underflow flaw that may permit an unauthenticated attacker to ship a malformed HTTP request, leading to a crash
  • CVE-2024-52320 (CVSS rating: 9.8) – An working system command injection flaw that may permit an unauthenticated attacker to ship instructions via a malicious HTTP request, leading to distant code execution
  • CVE-2024-48871 (CVSS rating: 9.8) – A stack-based buffer overflow flaw that may permit an unauthenticated attacker to ship a malicious HTTP request, leading to distant code execution

Profitable exploitation of the failings may allow an attacker to hijack the execution move by embedding a shellcode within the HTTP request and achieve the power to execute working system instructions.

Following accountable disclosure, the Taiwanese firm has rolled out patches for the shortcomings with model 1.305b241111 launched on November 15, 2024.

Discovered this text attention-grabbing? Observe us on Twitter  and LinkedIn to learn extra unique content material we publish.



You might also like

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

Tags: CriticalEnableExploitationFlawsNetworkRCESwitchesWGS804HPT
Previous Post

Why Cisco Leads with Wi-Fi 7: Reworking Future Connectivity

Next Post

MedOne Knowledge Facilities: The Strategic Benefit for International Tech Leaders

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board
Cyber Security

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

by Md Sazzad Hossain
June 15, 2025
Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets
Cyber Security

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

by Md Sazzad Hossain
June 14, 2025
The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

by Md Sazzad Hossain
June 14, 2025
Detecting Ransomware on Community: How Community Site visitors Evaluation Helps
Cyber Security

Detecting Ransomware on Community: How Community Site visitors Evaluation Helps

by Md Sazzad Hossain
June 13, 2025
What’s Zero Belief Structure? A Newbie’s Information
Cyber Security

What’s Zero Belief Structure? A Newbie’s Information

by Md Sazzad Hossain
June 13, 2025
Next Post
MedOne Knowledge Facilities: The Strategic Benefit for International Tech Leaders

MedOne Knowledge Facilities: The Strategic Benefit for International Tech Leaders

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Microsoft takes first step towards passwordless future

Microsoft takes first step towards passwordless future

April 2, 2025
Google DeepMind Researchers Suggest CaMeL: A Sturdy Protection that Creates a Protecting System Layer across the LLM, Securing It even when Underlying Fashions could also be Prone to Assaults

Google DeepMind Researchers Suggest CaMeL: A Sturdy Protection that Creates a Protecting System Layer across the LLM, Securing It even when Underlying Fashions could also be Prone to Assaults

March 27, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

Predicting Insurance coverage Prices with Linear Regression

Predicting Insurance coverage Prices with Linear Regression

June 15, 2025
Detailed Comparability » Community Interview

Detailed Comparability » Community Interview

June 15, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In