NA

CVE-2024-22894

Published: 30/01/2024 Updated: 05/03/2024
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 0

Vulnerability Summary

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote malicious users to execute arbitrary code via the password component in the shadow file.

Vulnerable Product Search on Vulmon Subscribe to Product

alpha-innotec heat_pumps_firmware

novelan heat_pumps_firmware

Github Repositories

CVE-2024-22894 Go to githubcom/Jaarden/CVE-2024-22894 for the latest updates Downloaded the latest heatpump firmware version wp2reg-V3880-9015 of wwwheatpump24com/DownloadAreaphp Within this firmware is a file called : wp2reg-V3880-9015\wp2reg-AlphaInnotech-prod\homewp2reg-V3880-9015_221213\share\shadow This contains a 3DES encrypted password root:M

CVE-2024-22894 Downloaded the latest heatpump firmware version wp2reg-V3880-9015 of wwwheatpump24com/DownloadAreaphp Within this firmware is a file called : wp2reg-V3880-9015\wp2reg-AlphaInnotech-prod\homewp2reg-V3880-9015_221213\share\shadow This contains a 3DES encrypted password root:MEfgX2vrPJzuE:0:0:99999:7::: of the system root user and when decrypted/c