Easywall 0.3.1 - Authentication Bypass via Command Injection in /ports-save Endpoint
Vulnerability Description
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58275
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Melvin Mejia
Affected Vendor
jpylypiw
View all reports →