OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
Vulnerability Description
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9166
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- CISA discovered a public Proof of Concept (PoC) as authored by Gjoko Krstic and reported it to Atelmo.
Affected Vendor
Atelmo
View all reports →