CVE-2024-7397 – Unauthenticated Command Injection
https://notcve.org/view.php?id=CVE-2024-7397
Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2. Korenix JetPort Series version 1.2 suffers from insufficient authentication, command injection, and plaintext communication vulnerabilities. • https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2024-7396 – Plaintext Communication
https://notcve.org/view.php?id=CVE-2024-7396
Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2. Korenix JetPort Series version 1.2 suffers from insufficient authentication, command injection, and plaintext communication vulnerabilities. • https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport • CWE-311: Missing Encryption of Sensitive Data •
CVE-2024-7395 – Insufficient Authentication
https://notcve.org/view.php?id=CVE-2024-7395
An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2. Korenix JetPort Series version 1.2 suffers from insufficient authentication, command injection, and plaintext communication vulnerabilities. • https://cyberdanube.com/de/en-multiple-vulnerabilities-in-korenix-jetport • CWE-287: Improper Authentication •