CVE-2024-4999

Ligowave Unity/Pro/Mimo/APC Arbitrary Command Injection

Description

A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.

Remediation

Workaround:

  • This product being EOL, Ligowave will not patch the vulnerability. If replacement of the EOL device is not possible, ensure access to the administration interface is restricted to administration network zones only, to reduce likelihood of exploitation.

Category

9.4
CVSS
Severity: Critical
CVSS 4.0 •
EPSS 0.55%
Third-Party Advisory onekey.com
Affected: Ligowave UNITY
Affected: Ligowave PRO
Affected: Ligowave MIMO
Affected: Ligowave APC Propeller
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-4999?
CVE-2024-4999 has been scored as a critical severity vulnerability.
How to fix CVE-2024-4999?
As a workaround for remediating CVE-2024-4999: This product being EOL, Ligowave will not patch the vulnerability. If replacement of the EOL device is not possible, ensure access to the administration interface is restricted to administration network zones only, to reduce likelihood of exploitation.
Is CVE-2024-4999 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-4999 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-4999?
CVE-2024-4999 affects Ligowave UNITY, Ligowave PRO, Ligowave MIMO, Ligowave APC Propeller.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.