Vulnerability Details CVE-2024-30220
Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-30220
-
cpe:2.3:h:planex:mzk-mf300hp2:-
-
cpe:2.3:h:planex:mzk-mf300n:-
-
cpe:2.3:o:planex:mzk-mf300hp2_firmware:-
-
cpe:2.3:o:planex:mzk-mf300hp2_firmware:1.16
-
cpe:2.3:o:planex:mzk-mf300hp2_firmware:1.17
-
cpe:2.3:o:planex:mzk-mf300hp2_firmware:1.18
-
cpe:2.3:o:planex:mzk-mf300n_firmware:-