CVE-2024-54849 describes a critical vulnerability in CP Plus CP-VNR-3104 B3223P22C02424 and its firmware, allowing attackers to extract a second RSA private key. This flaw, rated Medium severity (CVSS 5.9), enables unauthorized access to sensitive data or facilitates man-in-the-middle attacks due to insecure cryptographic storage (CWE-295). While the attack complexity is high, it requires no user interaction and can be executed remotely. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
b3223p22c02424CPE matchmatch criteria | cpe:2.3:o:cpplusworld:cp-vnr-3104_firmware:b3223p22c02424:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.