vendor:
Ewon Cosy+
by:
CodeB0ss
6.1
CVSS
HIGH
Command Injection
78
CWE
Product Name: Ewon Cosy+
Affected Version From: 21.2s7
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2024-33896
CPE: h:ewon:cosy_firmware:21.2s7
Platforms Tested: Windows 11 Home Edition
2024
Cosy+ firmware 21.2s7 – Command Injection
Due to improper handling of user-controlled configuration file parameters, an authenticated attacker can inject and run OS commands on the Ewon Cosy+ VPN gateway.
Mitigation:
Ensure proper input validation and neutralization of user-controlled data to prevent command injections. Regularly update to the latest firmware version provided by the vendor.