CVE-2024-52564 describes an undocumented feature vulnerability in UD-LT1 and UD-LT1/EX firmware versions 2.1.8 and earlier, allowing a remote attacker to disable the firewall. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and can lead to arbitrary OS command execution or device configuration alteration. While no public exploit code is available, the vulnerability is actively exploited in the wild, as evidenced by significant media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| I-O DATA DEVICE, INC. | UD-LT1 | firmware Ver.2.1.8 and earlierCNA affected | |
| I-O DATA DEVICE, INC. | UD-LT1/EX | firmware Ver.2.1.8 and earlierCNA affected |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.