CVE Published: 05/08/2024 |
CVE Updated: 07/08/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: Pimax |
Product: Pimax Play Status : PUBLISHED
CVE-2024-41889 Description
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.