ZeroHour

CVE-2024-48760

PoC niche

Unauthenticated RCE in GestióIP 3.5.7 via unrestricted file upload

CVSS 3.1
9.8 critical
EPSS
45%p99
Published
()
Modified
AI analysis

GestióIP version 3.5.7 contains an unrestricted file-upload flaw (CWE-434) in its upload function that can be triggered by a remote, unauthenticated attacker. By uploading a crafted perlcmd.cgi file that overwrites the original upload.cgi file, the attacker achieves remote command execution on the server hosting the application. Successful exploitation allows arbitrary code execution with critical impact across confidentiality, integrity, and availability (CVSS 9.8). Any organization running GestióIP 3.5.7 is affected, especially deployments whose web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation is reported and the flaw is not in CISA's KEV catalog, but a public proof-of-concept exists and EPSS assigns a 45.1% probability of exploitation within 30 days (99th percentile).

What to do: Restrict network access to the GestióIP web interface and check whether upload.cgi or perlcmd.cgi on your deployment has been modified or replaced, which would indicate compromise. Monitor the GestióIP project for a patched release (no fixed version is specified in the available data) and upgrade as soon as one is published. Given the public PoC and high EPSS score, prioritize review of any internet-exposed instances.

Affected
GestióIP (open-source IP address management tool)3.5.7 (the only version cited in the available data; other versions unspecified)
Estimated exposure
nichelikely hundreds of deployed instances, of which only a fraction are internet-exposed (niche open-source IPAM; no public install counts) — GestióIP is a specialized open-source IPAM tool typically installed on internal network-management servers rather than mass-market software, so the plausible affected population is small, though no authoritative install or scan counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

Vendors
gestioip
Products
gestioip
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.