CVE-2024-22807 is a medium-severity vulnerability affecting Tormach xsTECH CNC Routers running PathPilot Controller v2.9.6. An authenticated attacker can exploit this flaw remotely to erase a critical flash memory sector, leading to a denial of service through loss of network connectivity and firmware corruption. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for significant operational disruption to affected CNC machines warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.9.6CPE matchmatch criteria | cpe:2.3:a:tormach:pathpilot_controller:2.9.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.