Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-48760 | Unauthenticated RCE in GestióIP 3.5.7 via unrestricted file upload GestióIP version 3.5.7 contains an unrestricted file-upload flaw (CWE-434) in its upload function that can be triggered by a remote, unauthenticated attacker. By uploading a crafted perlcmd.cgi file that overwrites the original upload.cgi file, the attacker achieves remote command execution on the server hosting the application. Successful exploitation allows arbitrary code execution with critical impact across confidentiality, integrity, and availability (CVSS 9.8). Any organization running GestióIP 3.5.7 is affected, especially deployments whose web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation is reported and the flaw is not in CISA's KEV catalog, but a public proof-of-concept exists and EPSS assigns a 45.1% probability of exploitation within 30 days (99th percentile). Do: Restrict network access to the GestióIP web interface and check whether upload.cgi or perlcmd.cgi on your deployment has been modified or replaced, which would indicate compromise. Monitor the GestióIP project for a patched release (no fixed version is specified in the available data) and upgrade as soon as one is published. Given the public PoC and high EPSS score, prioritize review of any internet-exposed instances. | 9.8 group max | 45% | PoC |
| nichelikely hundreds of deployed instances, of which only a fraction are internet-exposed (niche open-source IPAM; no public install counts) |