{ "id": "CVE-2024-4999", "sourceIdentifier": "research@onekey.com", "published": "2024-05-16T13:15:48.357", "lastModified": "2024-05-16T13:15:48.357", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote\u00a0attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352." } ], "metrics": {}, "weaknesses": [ { "source": "research@onekey.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-77" } ] } ], "references": [ { "url": "https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/", "source": "research@onekey.com" } ] }