← back
CVE-2024-54457highCWE-1242

CVE-2024-54457

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
In short

A logged-in user can enable telnet service on certain AE1021 devices due to hidden features in the firmware. This is dangerous because telnet transmits data without encryption, exposing sensitive information and device access.

Technical detail

CWE-1242 involves undocumented features (chicken bits) in AE1021 and AE1021PE firmware ≤2.0.10 that permit authenticated users to activate telnet service. An attacker with valid credentials can exploit this to establish unencrypted remote access, potentially leading to credential interception and further system compromise.

Summary generated and translated by AI from the official description.
Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to enable telnet service.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H