CRITICAL🇵🇱 Wersja polska

CVE-2024-55547

CVSS 9.3v4.0pub. 2024-12-10upd. 2025-11-03

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

🤖 AI Analysis
How it works

The attacker sends a crafted SNMP query containing malicious data to an SNMP object handled by the NET-SNMP library on the device. The input data is not properly filtered or validated (CWE-77 — command injection), allowing additional system commands to be embedded. These commands are then executed by the device's operating system with the privileges of the process handling SNMP.

Impact

An unauthenticated remote attacker can execute arbitrary system commands on the ORing IAP-420 device, leading to complete device takeover and compromise of confidentiality, integrity, and availability of the system.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. As a temporary measure, it is recommended to restrict access to the SNMP interface of the device at the firewall level to trusted hosts and disable SNMP if the service is not required.

Who is affected

ORing IAP-420 with firmware version up to and including 2.01e.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Oringnet Iap 420

    HW
    Oringnet
    all versions
  • Oringnet Iap 420 Firmware

    OS
    Oringnet
    ≤ 2.01e
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-3203CRITICAL9.8PL ✓same product

ORing IAP-420(+): domyślny serwer telnet z zakodowanymi na stałe poświadczeniami

CVE-2024-55544HIGH8.7same product

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS leve...

CVE-2024-55545HIGH7.1same product

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affec...

CVE-2024-55546HIGH7.1same product

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issu...

CVE-2024-5411HIGH8.7same product

Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows aut...