CVE-2024-52564
https://notcve.org/view.php?id=CVE-2024-52564
05 Dec 2024 — Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. • https://jvn.jp/en/jp/JVN46615026 • CWE-1242: Inclusion of Undocumented Features or Chicken Bits •
CVE-2024-47133
https://notcve.org/view.php?id=CVE-2024-47133
05 Dec 2024 — UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands. UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands. • https://jvn.jp/en/jp/JVN46615026 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •