CVE-2024-55515

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:raisecom:msg2300_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:raisecom:msg2100e_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2100e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:raisecom:msg2200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2200:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:raisecom:msg1200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg1200:-:*:*:*:*:*:*:*

History

28 Apr 2025, 17:13

Type Values Removed Values Added
References () https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060 - () https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060 - Third Party Advisory
Summary
  • (es) Se encontró una vulnerabilidad en Raisecom MSG1200, MSG2100E, MSG2200 y MSG2300 3.90. El componente afectado por este problema es /upload_ipslib.php en la interfaz web. Al manipular un nombre de formulario adecuado, se pueden cargar archivos arbitrarios.
First Time Raisecom msg1200 Firmware
Raisecom
Raisecom msg2100e Firmware
Raisecom msg2200
Raisecom msg2200 Firmware
Raisecom msg1200
Raisecom msg2100e
Raisecom msg2300 Firmware
Raisecom msg2300
CPE cpe:2.3:h:raisecom:msg2300:-:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2200:-:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg1200:-:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg2300_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:h:raisecom:msg2100e:-:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg2100e_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg2200_firmware:3.90:*:*:*:*:*:*:*
cpe:2.3:o:raisecom:msg1200_firmware:3.90:*:*:*:*:*:*:*

18 Dec 2024, 16:15

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

17 Dec 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-17 20:15

Updated : 2025-04-28 17:13


NVD link : CVE-2024-55515

Mitre link : CVE-2024-55515

CVE.ORG link : CVE-2024-55515


JSON object : View

Products Affected

raisecom

  • msg1200_firmware
  • msg2300_firmware
  • msg1200
  • msg2200
  • msg2200_firmware
  • msg2100e_firmware
  • msg2100e
  • msg2300
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')