← Vulnerability feed

Vulnerability record · CVE-2024-7469 · published 5 August 2024

CVE-2024-7469: Raisecom msg2300 firmware os command injection vulnerability

RRaisecom · Msg2300 Firmware

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of the file /vpn/list_vpn_web_custom.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273562 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

5.3 CVSS 4.0 Medium EPSS 25% · top 2.2% CWE-78 · OS command injection
5.3CVSS 4.0 base score, v2 6.5
25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been declared as critical. This vulnerability affects the function sslvpn_config_mod of the file /vpn/list_vpn_web_custom.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273562 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/sQrromK7x42JbLgY/Command%20Injection%20Vulnerability%2 Broken LinkExploitTechnical DescriptionThird Party Advisory
https://vuldb.com/?ctiid.273562 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.273562 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.385349 Third Party AdvisoryVDB Entry

Track CVE-2024-7469 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-55515Raisecom msg2300 firmware path traversal vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the…EPSS 0.60%9.1CVE-2024-55516Raisecom msg2300 firmware path traversal vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on…EPSS 0.52%9.1CVE-2024-55513Raisecom msg2300 firmware path traversal vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on …EPSS 0.52%6.3CVE-2024-55514Raisecom msg2300 firmware unrestricted file upload vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the …EPSS 0.24%5.3CVE-2024-7470Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been rated as critical. This issue affects the function ssl…EPSS 25%5.3CVE-2024-7467Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90 and classified as critical. Affected by this issue is the function …EPSS 23%5.3CVE-2024-7468Raisecom msg2300 firmware os command injection vulnerabilityA vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslv…EPSS 25%5.3CVE-2024-7120Raisecom MSG Gateway Web Interface OS Command InjectionRaisecom MSG1200, MSG2100E, MSG2200 and MSG2300 firmware 3.90 contain an OS command injection flaw in list_base_config.php of the web interface, reac…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-7469), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.