← Vulnerability feed

Vulnerability record · CVE-2024-55513 · published 17 December 2024

CVE-2024-55513: Raisecom msg2300 firmware path traversal vulnerability

RRaisecom · Msg2300 Firmware

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.

9.1 CVSS 3.1 Critical EPSS 0.52% · top 58.2% CWE-22 · Path traversal
9.1CVSS 3.1 base score
0.52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-55513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-55515Raisecom msg2300 firmware path traversal vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the…EPSS 0.60%9.1CVE-2024-55516Raisecom msg2300 firmware path traversal vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on…EPSS 0.52%6.3CVE-2024-55514Raisecom msg2300 firmware unrestricted file upload vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the …EPSS 0.24%5.3CVE-2024-7469Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the f…EPSS 25%5.3CVE-2024-7470Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function ssl…EPSS 25%5.3CVE-2024-7467Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function …EPSS 23%5.3CVE-2024-7468Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslv…EPSS 25%5.3CVE-2024-7120Raisecom MSG Gateway Web Interface OS Command InjectionRaisecom MSG1200, MSG2100E, MSG2200 and MSG2300 firmware 3.90 contain an OS command injection flaw in list_base_config.php of the web interface, reac…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-55513), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.