Wednesday, February 12, 2025
HomeCVE/vulnerabilityI-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks

I-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks

Published on

SIEM as a Service

Follow Us on Google News

I-O DATA DEVICE, INC. has announced that several critical vulnerabilities in their UD-LT1 and UD-LT1/EX routers are being actively exploited.

These vulnerabilities pose significant risks to users, necessitating urgent attention and action. Below is a detailed look at each vulnerability, its potential impact, and the solutions provided.

CVE-2024-45841: Incorrect Permission Assignment for Critical Resource

This vulnerability, rated with a CVSS score of 6.5, involves incorrect permission assignments that allow attackers with guest-level access to retrieve files containing sensitive credential information.

Such exposure can lead to further unauthorized access and exploitation of the network.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

CVE-2024-47133: OS Command Injection

With a CVSS score of 7.2, this vulnerability permits a logged-in user with administrative permissions to execute arbitrary operating system commands on the device.

The exploitation of this vulnerability can severely compromise the integrity of the affected router, potentially allowing attackers to manipulate system settings or access sensitive data.

CVE-2024-52564: Inclusion of Undocumented Features

This vulnerability, scoring 7.5 on the CVSS scale, allows remote attackers to disable firewall protections, execute arbitrary commands, and alter device configurations without the need for authentication.

The presence of undocumented features makes this vulnerability particularly dangerous, as it can lead to extensive unauthorized control over the router.

According to the JVN report, exploiting these vulnerabilities can lead to serious repercussions for users, including unauthorized access, data theft, and loss of device control.

The potential for attackers to execute arbitrary commands and alter firewall settings elevates the risk of significant network breaches.

I-O DATA DEVICE, INC. advises users to update their device firmware to address these vulnerabilities.

Updates for CVE-2024-45841 and CVE-2024-47133 are scheduled for release by December 18, 2024. Meanwhile, patches for CVE-2024-52564 are already available with firmware version 2.1.9 for both UD-LT1 and UD-LT1/EX models.

Until firmware updates are applied, users should modify device settings based on the developer’s guidance to mitigate the risks associated with these vulnerabilities.

I-O DATA DEVICE, INC. has acknowledged the vulnerabilities and is actively working to provide effective solutions. Users can access further details and updates through the company’s official website.

The vulnerabilities were identified by Takeshi Kuramori, Kaori Takashima, and Kohei Masumi at the National Institute of Information and Communications Technology, along with Chuya Hayakawa and Ryo Kamino from 00One, Inc.

JPCERT/CC played a crucial role in coordinating the response to these vulnerabilities. For more technical insights, users are encouraged to consult JPCERT/CC’s analysis and recommendations.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

0-Day Vulnerability in Windows Storage Allow Hackers to Delete the Target Files Remotely

A newly discovered 0-day vulnerability in Windows Storage has sent shockwaves through the cybersecurity...

Ratatouille Malware Bypass UAC Control & Exploits I2P Network to Launch Cyber Attacks

A newly discovered malware, dubbed "Ratatouille" (or I2PRAT), is raising alarms in the cybersecurity...

Sandworm APT Hackers Weaponize Microsoft KMS Activation Tools To Compromise Windows

In a sophisticated cyber-espionage operation, the Russian state-sponsored hacking group Sandworm (APT44), linked to...

Hackers Can Exploit “Wormable” Windows LDAP RCE Vulnerability for Remote Attacks

A critical new vulnerability in Microsoft’s Windows Lightweight Directory Access Protocol (LDAP), tagged as...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

0-Day Vulnerability in Windows Storage Allow Hackers to Delete the Target Files Remotely

A newly discovered 0-day vulnerability in Windows Storage has sent shockwaves through the cybersecurity...

Ratatouille Malware Bypass UAC Control & Exploits I2P Network to Launch Cyber Attacks

A newly discovered malware, dubbed "Ratatouille" (or I2PRAT), is raising alarms in the cybersecurity...

Sandworm APT Hackers Weaponize Microsoft KMS Activation Tools To Compromise Windows

In a sophisticated cyber-espionage operation, the Russian state-sponsored hacking group Sandworm (APT44), linked to...