CVE-2024-28008
CRITICALDescription
Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command via the internet.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nec | aterm_wg1800hp4_firmware |
| nec | aterm_wg1800hp4 |
| nec | aterm_wg1200hs3_firmware |
| nec | aterm_wg1200hs3 |
| nec | aterm_wg1900hp2_firmware |
| nec | aterm_wg1900hp2 |
| nec | aterm_wg1200hp3_firmware |
| nec | aterm_wg1200hp3 |
| nec | aterm_wg1800hp3_firmware |
| nec | aterm_wg1800hp3 |
| nec | aterm_wg1200hs2_firmware |
| nec | aterm_wg1200hs2 |
| nec | aterm_wg1900hp_firmware |
| nec | aterm_wg1900hp |
| nec | aterm_wg1200hp2_firmware |
| nec | aterm_wg1200hp2 |
| nec | aterm_w1200ex-ms_firmware |
| nec | aterm_w1200ex-ms |
| nec | aterm_wg1200hs_firmware |
| nec | aterm_wg1200hs |
| nec | aterm_wg1200hp_firmware |
| nec | aterm_wg1200hp |
| nec | aterm_wf300hp2_firmware |
| nec | aterm_wf300hp2 |
| nec | aterm_w300p_firmware |
| nec | aterm_w300p |
| nec | aterm_wf800hp_firmware |
| nec | aterm_wf800hp |
| nec | aterm_wr8165n_firmware |
| nec | aterm_wr8165n |
| nec | aterm_wg2200hp_firmware |
| nec | aterm_wg2200hp |
| nec | aterm_wf1200hp2_firmware |
| nec | aterm_wf1200hp2 |
| nec | aterm_wg1800hp2_firmware |
| nec | aterm_wg1800hp2 |
| nec | aterm_wf1200hp_firmware |
| nec | aterm_wf1200hp |
| nec | aterm_wg600hp_firmware |
| nec | aterm_wg600hp |
| nec | aterm_wg300hp_firmware |
| nec | aterm_wg300hp |
| nec | aterm_wf300hp_firmware |
| nec | aterm_wf300hp |
| nec | aterm_wg1800hp_firmware |
| nec | aterm_wg1800hp |
| nec | aterm_wg1400hp_firmware |
| nec | aterm_wg1400hp |
| nec | aterm_wr8175n_firmware |
| nec | aterm_wr8175n |
| nec | aterm_wr9300n_firmware |
| nec | aterm_wr9300n |
| nec | aterm_wr8750n_firmware |
| nec | aterm_wr8750n |
| nec | aterm_wr8160n_firmware |
| nec | aterm_wr8160n |
| nec | aterm_wr9500n_firmware |
| nec | aterm_wr9500n |
| nec | aterm_wr8600n_firmware |
| nec | aterm_wr8600n |
| nec | aterm_wr8370n_firmware |
| nec | aterm_wr8370n |
| nec | aterm_wr8170n_firmware |
| nec | aterm_wr8170n |
| nec | aterm_wr8700n_firmware |
| nec | aterm_wr8700n |
| nec | aterm_wr8300n_firmware |
| nec | aterm_wr8300n |
| nec | aterm_wr8150n_firmware |
| nec | aterm_wr8150n |
| nec | aterm_wr4100n_firmware |
| nec | aterm_wr4100n |
| nec | aterm_wr4500n_firmware |
| nec | aterm_wr4500n |
| nec | aterm_wr8100n_firmware |
| nec | aterm_wr8100n |
| nec | aterm_wr8500n_firmware |
| nec | aterm_wr8500n |
| nec | aterm_cr2500p_firmware |
| nec | aterm_cr2500p |
| nec | aterm_wr8400n_firmware |
| nec | aterm_wr8400n |
| nec | aterm_wr8200n_firmware |
| nec | aterm_wr8200n |
| nec | aterm_wr1200h_firmware |
| nec | aterm_wr1200h |
| nec | aterm_wr7870s_firmware |
| nec | aterm_wr7870s |
| nec | aterm_wr6670s_firmware |
| nec | aterm_wr6670s |
| nec | aterm_wr7850s_firmware |
| nec | aterm_wr7850s |
| nec | aterm_wr6650s_firmware |
| nec | aterm_wr6650s |
| nec | aterm_wr6600h_firmware |
| nec | aterm_wr6600h |
| nec | aterm_wr7800h_firmware |
| nec | aterm_wr7800h |
| nec | aterm_wm3400rn_firmware |
| nec | aterm_wm3400rn |
| nec | aterm_wm3450rn_firmware |
| nec | aterm_wm3450rn |
| nec | aterm_wm3500r_firmware |
| nec | aterm_wm3500r |
| nec | aterm_wm3600r_firmware |
| nec | aterm_wm3600r |
| nec | aterm_wm3800r_firmware |
| nec | aterm_wm3800r |
| nec | aterm_wr8166n_firmware |
| nec | aterm_wr8166n |
| nec | aterm_mr01ln_firmware |
| nec | aterm_mr01ln |
| nec | aterm_mr02ln_firmware |
| nec | aterm_mr02ln |
| nec | aterm_wg1810hp\(je\)_firmware |
| nec | aterm_wg1810hp\(je\) |
| nec | aterm_wg1810hp\(mf\)_firmware |
| nec | aterm_wg1810hp\(mf\) |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-28008? +
How severe is CVE-2024-28008? +
What products are affected by CVE-2024-28008? +
How do I check if I'm vulnerable to CVE-2024-28008? +
Related Vulnerabilities
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with …
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable …
Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege …
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication …