← Back to CVE List

CVE-2024-34852

Published: 2024-05-28T17:15Z
Last Modified: 2024-11-21T09:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this vulnerability may allow the attacker to execute system commands. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt