CVE-2024-3871
Published: 16 April 2024
Summary
CVE-2024-3871 is a critical-severity Command Injection (CWE-77) vulnerability in Onekey (inferred from references). Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 13.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-32439
Vulnerability details
The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote…
more
code execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Platform-independent managed code eliminates the need for unchecked native buffer copies that are the root cause of classic buffer overflows.