vendor:
Electrolink FM/DAB/TV Transmitter
by:
Anonymous
6.1
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Electrolink FM/DAB/TV Transmitter
Affected Version From: 01.09, 1.4, 01.06, 2.1
Affected Version To: 01.07, 1.2, 01.03, 2.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Electrolink FM/DAB/TV Transmitter Pre-Auth MPFS Image Remote Code Execution
Electrolink FM/DAB/TV Transmitter devices with web version 01.09, 01.08, 01.07, display version 1.4, 1.2, control unit version 01.06, 01.04, 01.03, and firmware version 2.1 are vulnerable to a pre-authentication MPFS image remote code execution. An attacker could exploit this vulnerability to execute arbitrary code on the affected system.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the affected devices, apply the latest security patches provided by the vendor, and regularly monitor for any unauthorized access or unusual activities.