← Back to browse · API

CVE-2023-24479

Severity
CRITICAL
CVSS
9.8
EPSS
0.01711
Risk score
39.8
CISA KEV
No
PoC
No
Published
2023-10-11
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-28497, GHSA-PPWP-GX43-6M45
Products
Yifan:YF325 v1.0_20221108
Sources
euvd EUVD-2023-28497

Description

An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.

References