VYPR
Critical severity9.8NVD Advisory· Published Mar 18, 2025· Updated Jun 17, 2026

CVE-2024-8997

CVE-2024-8997

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection.

This issue affects EVC04 Configuration Interface: before V3.187, V4.53.

Affected products

3
  • cpe:2.3:a:vestel:evc04_configuration_interface:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:vestel:evc04_configuration_interface:*:*:*:*:*:*:*:*range: <=18.03.2025
    • (no CPE)range: <V3.187, <V4.53
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.