CVE-2024-54849

An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.
References
Link Resource
https://nvd.nist.gov/vuln/detail/CVE-2020-15522 Not Applicable
https://payatu.com/blog/solving-the-problem-of-encrypted-firmware/ Technical Description Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:cpplusworld:cp-vnr-3104_firmware:b3223p22c02424:*:*:*:*:*:*:*
cpe:2.3:h:cpplusworld:cp-vnr-3104:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-10 17:15

Updated : 2025-10-02 16:54


NVD link : CVE-2024-54849

Mitre link : CVE-2024-54849

CVE.ORG link : CVE-2024-54849


JSON object : View

Products Affected

cpplusworld

  • cp-vnr-3104
  • cp-vnr-3104_firmware
CWE
CWE-295

Improper Certificate Validation