← Back to browse · API

CVE-2024-42905

Severity
CRITICAL
CVSS
9.8
EPSS
0.15482
Risk score
44.62
CISA KEV
No
PoC
No
Published
2024-08-28
Modified
2024-08-28
First seen
2026-08-07
Aliases
EUVD-2024-39821, GHSA-HVW3-J8WV-XPG5
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-39821

Description

Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.

References