CVE-2024-4584 is a significant information disclosure vulnerability affecting Faraday GM8181 and GM828x models up to version 20240429. The vulnerability resides in the /command_port.ini file, which, when manipulated, can lead to unauthorized access to sensitive system information. This vulnerability is particularly concerning because it can be exploited remotely without requiring authentication, making it a prime target for attackers. The public availability of exploits further exacerbates the risk, as malicious actors can easily leverage these to gain unauthorized access to affected systems. The vulnerability has been assigned a CVSS v3.1 base score of 7.5, reflecting its high severity and the potential impact on confidentiality. Despite the critical nature of this vulnerability, the vendor has not responded to disclosure attempts, leaving users exposed to potential exploitation. The lack of vendor response underscores the importance of users taking immediate action to mitigate the risk. The vulnerability's remote exploitability, combined with the absence of vendor support, makes it a pressing issue for organizations using these devices. Users are advised to implement mitigation strategies promptly to protect sensitive data from unauthorized access.
|