ZeroHour

CVE-2024-8997

CVSS 3.1
9.8 critical
EPSS
<1%p36
Published
()
Modified
Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53.

Vendors
vestel
Products
evc04 configuration interface
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.