Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2024-58277: CWE-312 Cleartext Storage of Sensitive Information in R Radio Network Radio Network FM Transmitter

0
High
VulnerabilityCVE-2024-58277cvecve-2024-58277cwe-312
Published: Thu Dec 04 2025 (12/04/2025, 20:42:19 UTC)
Source: CVE Database V5
Vendor/Project: R Radio Network
Product: Radio Network FM Transmitter

Description

R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.

AI-Powered Analysis

AILast updated: 12/04/2025, 21:09:42 UTC

Technical Analysis

CVE-2024-58277 is a vulnerability categorized under CWE-312 (Cleartext Storage of Sensitive Information) found in R Radio Network FM Transmitter version 1.07. The flaw exists because the device stores the admin user's password in cleartext and exposes it through the system.cgi endpoint without requiring authentication. This design weakness allows any remote attacker to retrieve the admin password directly, bypassing all authentication mechanisms. Once the attacker obtains the password, they can access the FM transmitter's administrative interface and manipulate FM station settings, potentially disrupting broadcast operations or injecting unauthorized content. The vulnerability is remotely exploitable over the network without any user interaction or privileges, making it highly accessible to attackers. The CVSS 4.0 base score is 8.7, reflecting the critical confidentiality impact and ease of exploitation. No patches or exploits are currently publicly available, but the risk remains high due to the sensitive nature of the device and its role in broadcast infrastructure. The vulnerability highlights poor security design in embedded device credential management and the need for encrypted storage and secure access controls.

Potential Impact

For European organizations, especially broadcasters and media companies using R Radio Network FM Transmitters, this vulnerability poses a significant risk of unauthorized access and control over FM transmission settings. Attackers could disrupt broadcast services, manipulate transmitted content, or cause denial of service by misconfiguring the device. This could lead to reputational damage, regulatory penalties, and loss of audience trust. Critical infrastructure operators relying on these devices may face operational disruptions. The confidentiality breach of admin credentials also increases the risk of lateral movement within organizational networks if the device is connected to broader IT infrastructure. Given the ease of exploitation and lack of authentication required, the threat is particularly acute for organizations with exposed or poorly segmented network environments.

Mitigation Recommendations

1. Immediately isolate affected R Radio Network FM Transmitter devices from public and untrusted networks to reduce exposure. 2. Implement strict network segmentation and firewall rules to restrict access to the system.cgi endpoint only to trusted administrators. 3. Monitor network traffic for unusual access attempts to the transmitter's management interface. 4. Enforce strong password policies and consider changing default or known passwords if possible. 5. Engage with the vendor for firmware updates or patches addressing this vulnerability; apply them promptly once available. 6. If patching is delayed, consider deploying compensating controls such as VPN access for management interfaces or multi-factor authentication proxies. 7. Conduct security audits of all broadcast infrastructure devices to identify similar credential storage or access control weaknesses. 8. Train operational staff on recognizing signs of device compromise and incident response procedures.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2025-12-04T16:29:09.649Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6931f4df0459f550ecf89e3a

Added to database: 12/4/2025, 8:53:51 PM

Last enriched: 12/4/2025, 9:09:42 PM

Last updated: 12/5/2025, 2:45:59 AM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats