Inclusion of Undocumented Features or Chicken Bits in AE1021 and AE1021PE - CVE-2024-54457

 

Inclusion of Undocumented Features or Chicken Bits in AE1021 and AE1021PE - CVE-2024-54457

Published: December 16, 2024


Vulnerability identifier: #VU101782
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-54457
CWE-ID: CWE-1242
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: FXC
Affected software:
AE1021
AE1021PE

Detailed vulnerability description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to inclusion of undocumented features. A remote administrator can enable telnet service.


How to mitigate CVE-2024-54457

Install updates from vendor's website.

Sources