CVE-2024-48760
PoC nicheUnauthenticated RCE in GestióIP 3.5.7 via unrestricted file upload
GestióIP version 3.5.7 contains an unrestricted file-upload flaw (CWE-434) in its upload function that can be triggered by a remote, unauthenticated attacker. By uploading a crafted perlcmd.cgi file that overwrites the original upload.cgi file, the attacker achieves remote command execution on the server hosting the application. Successful exploitation allows arbitrary code execution with critical impact across confidentiality, integrity, and availability (CVSS 9.8). Any organization running GestióIP 3.5.7 is affected, especially deployments whose web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation is reported and the flaw is not in CISA's KEV catalog, but a public proof-of-concept exists and EPSS assigns a 45.1% probability of exploitation within 30 days (99th percentile).
What to do: Restrict network access to the GestióIP web interface and check whether upload.cgi or perlcmd.cgi on your deployment has been modified or replaced, which would indicate compromise. Monitor the GestióIP project for a patched release (no fixed version is specified in the available data) and upgrade as soon as one is published. Given the public PoC and high EPSS score, prioritize review of any internet-exposed instances.
| GestióIP (open-source IP address management tool) | 3.5.7 (the only version cited in the available data; other versions unspecified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.
- Vendors
- gestioip
- Products
- gestioip
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.