CVE-2024-20287 is a command injection vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point. An authenticated, remote attacker can exploit this by sending crafted HTTP requests due to improper input validation. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating that a successful exploit could allow an attacker to execute arbitrary commands with root privileges, leading to high impact on confidentiality, integrity, and availability. While requiring valid administrative credentials, there is no evidence of active exploitation (KEV: No), nor publicly available exploit code (Metasploit, Nuclei, ExploitDB: None). However, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:wap371_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.