CVE-2024-4639 | OnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSec
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Conclusion & alert: CVE-2024-4639 is rated Moderate Risk (55.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.19%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2024-4639
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).