VYPR
Medium severity6.3NVD Advisory· Published Apr 16, 2024· Updated Apr 15, 2026

CVE-2024-30567

CVE-2024-30567

Description

Authenticated remote code execution in JNT Liftcom UMS via the Network Troubleshooting functionality allows attackers to execute arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated remote code execution in JNT Liftcom UMS via the Network Troubleshooting functionality allows attackers to execute arbitrary commands.

Vulnerability

Overview An authenticated remote code execution vulnerability exists in JNT Telecom JNT Liftcom UMS version V1.J Core Version JM-V15. The flaw resides in the "Network Troubleshooting" functionality of the web interface. Improper input validation allows an authenticated attacker to inject and execute arbitrary operating system commands [1].

Exploitation

Conditions To exploit this vulnerability, an attacker must have valid credentials to the JNT Liftcom UMS web interface. With network access to the management interface, they can send specially crafted HTTP requests to the Network Troubleshooting feature, which executes commands with elevated privileges. No additional authentication or network position is required beyond valid credentials and network connectivity [1].

Impact

Successful exploitation enables arbitrary command execution on the underlying system. This can lead to full system compromise, including data exfiltration, malware installation, and potential lateral movement within the network. The vulnerability is rated Medium with a CVSS v3 score of 6.3, indicating significant impact with moderate complexity [1].

Mitigation

Status As of the publication date, no official patch has been released by JNT Telecom. Users should consider restricting network access to the management interface, implementing strong authentication mechanisms, and monitoring for suspicious activity. It is advisable to contact the vendor for updates [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

Synthesis attempt was rejected by the grounding validator. Re-run pending.

References

1

News mentions

0

No linked articles in our index yet.