RCE in RAISECOM Gateway Devices

ISGroup Cybersecurity

RAISECOM Gateway is vulnerable to command injection via the template parameter in the list_base_config.php script. This vulnerability allows remote attackers to execute arbitrary commands on affected devices. Active attacks exploiting this flaw have been observed, with potential significant impacts on network security.

ProductRAISECOM Gateway
Date2024-08-08 09:17:53

Technical Summary

RAISECOM Gateway devices are vulnerable to command injection via the template parameter in the list_base_config.php script. This vulnerability allows remote attackers to execute arbitrary commands and is currently being actively exploited.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert