Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-45841

Quick assessment

Affected
I-O DATA DEVICE, INC. UD-LT1
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX都是日本艾欧资讯(I-O Data Device)公司的产品。I-O Data Device UD-LT1是一款混合LTE路由器。I-O Data Device UD-LT1/EX是一款混合LTE路由器 ,是IO DATA UD-LT1路由器的后续升级版本。 I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX存在安全漏洞,该漏洞源于存在敏感资源的权限配置错误,允许具

AI Predicted 6.5 Difficulty: Easy EPSS 0.47% · P39

Possible ATT&CK Techniques 1 AI

T1552.005 · Cloud Instance Metadata API
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-45841

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
关键资源的不正确权限授予
Source: CVE Program / CVE List V5
Vulnerability Title
I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX都是日本艾欧资讯(I-O Data Device)公司的产品。I-O Data Device UD-LT1是一款混合LTE路由器。I-O Data Device UD-LT1/EX是一款混合LTE路由器 ,是IO DATA UD-LT1路由器的后续升级版本。 I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX存在安全漏洞,该漏洞源于存在敏感资源的权限配置错误,允许具
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
I-O DATA DEVICE, INC. UD-LT1 firmware Ver.2.1.9 and earlier -
I-O DATA DEVICE, INC. UD-LT1/EX firmware Ver.2.1.9 and earlier -

II. Public POCs for CVE-2024-45841

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-45841

请登录查看更多情报信息。

Vendor Advisories for CVE-2024-45841 (2)

Same Patch Batch · I-O DATA DEVICE, INC. · 2024-12-05 · 3 CVEs total

CVE-2024-52564 I-O Data Device UD-LT1和UD-LT1/EX 安全漏洞
CVE-2024-47133 I-O Data Device UD-LT1和I-O Data Device UD-LT1/EX 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2024-45841

No comments yet


Leave a comment