CVE-2024-58277
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-04

Last updated on: 2025-12-08

Assigner: VulnCheck

Description
R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-04
Last Modified
2025-12-08
Generated
2026-06-16
AI Q&A
2025-12-04
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
r_radio_network fm_transmitter 1.07
r_radio_network fm_transmitter 1.09
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint. This access enables attackers to bypass authentication and gain control over FM station setup functions.

Impact Analysis

The vulnerability can lead to unauthorized control of the FM transmitter's administrative functions, potentially allowing attackers to manipulate FM station settings, disrupt service, or compromise the device's operation.

Detection Guidance

This vulnerability can be detected by sending an unauthenticated HTTP request to the system.cgi endpoint of the R Radio Network FM Transmitter version 1.07. For example, using a command like `curl http://<target-ip>/system.cgi` can reveal an HTML page containing the admin user's clear-text password in a password input field if the device is vulnerable. [2]

Mitigation Strategies

The immediate mitigation step is to upgrade the R Radio Network FM Transmitter from version 1.07 to version 1.09, which the vendor released to address this vulnerability. Until the upgrade can be applied, restrict network access to the device's system.cgi endpoint to trusted users only, and monitor for any unauthorized access attempts. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-58277. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart