NVD Vulnerability Detail
Search Exploit, PoC
CVE-2024-40893
Summary

Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software
versions before 1.979. A physically close
attacker that is authenticated to the Bluetooth Low-Energy (BTLE) interface can use the network configuration service to inject commands in various configuration parameters including networkConfig.Interface.Phy.Eth0.Extra.PingTestIP, networkConfig.Interface.Phy.Eth0.Extra.DNSTestDomain, and networkConfig.Interface.Phy.Eth0.Gateway6. Additionally, because the configuration can be synced to the Firewalla cloud, the attacker may be able to persist access even after hardware resets and firmware re-flashes.

Publication Date Aug. 13, 2024, 4:15 a.m.
Registration Date Aug. 26, 2024, 5:03 p.m.
Last Update Aug. 22, 2024, 3:15 a.m.
Related information, measures and tools
Common Vulnerabilities List