vendor:
GestioIP
by:
m4xth0r (Maximiliano Belino)
6.1
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: GestioIP
Affected Version From: 3.5.2007
Affected Version To: 3.5.2007
Patch Exists: NO
Related CWE: CVE-2024-48760
CPE: a:gestioip:gestioip:3.5.7
Platforms Tested: Kali Linux
2025
GestioIP 3.5.7 – Remote Command Execution (RCE)
The GestioIP version 3.5.7 is vulnerable to remote command execution. An attacker can exploit this vulnerability to execute arbitrary commands on the target server. This exploit is identified by CVE-2024-48760.
Mitigation:
To mitigate this vulnerability, it is recommended to update GestioIP to a patched version or apply the vendor-supplied fixes. Additionally, restrict network access to the application and implement strong authentication mechanisms.