CVE-2024-4999 is a critical vulnerability (CVSS 9.4) affecting the web-based management interface of several Ligowave devices, including UNITY, PRO, MIMO, and APC Propeller series. This flaw, categorized as CWE-77 (Improper Neutralization of Special Elements used in a Command), allows an authenticated remote attacker to execute arbitrary commands with elevated privileges. While the attack complexity is low and no user interaction is required, the high privileges needed for exploitation somewhat mitigate the immediate risk. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ligowave | APC Propeller | >= 0, <= 2-5.95-4.rt3352CNA affecteddefault unaffected | |
| Ligowave | MIMO | >= 0, <= 6.95-1.rt2880CNA affecteddefault unaffected | |
| Ligowave | PRO | >= 0, <= 6.95-1.rt3883CNA affecteddefault unaffected | |
| Ligowave | UNITY | >= 0, <= 6.95-2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.