CVE-2024-28138

CVE-2024-28138: OS Command Injection

Vendor Image Access Gmbh
Product Scan2Net
Weakness CWE-78
Published December 10, 2024
Last update November 3, 2025

CVSS base score

What the vulnerability does

01Description

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.

Key dates

02Disclosure timeline

December 10, 2024 CVE published
November 3, 2025 Record updated