Junglewise Threat Intelligence

CVE-2024-44598: FNT Software FNT Command remote code execution via file upload in C Base Module

CVE-2024-44598 · Severity: high · CVSS 8.8 · Published 2025-12-15

Executive brief

FNT Command, a software suite used for managing IT and telecommunications infrastructure, contains a security flaw that allows an authorized user to upload and run malicious code on the server. If exploited, an attacker could gain full control over the system, allowing them to steal sensitive infrastructure data, modify configurations, or disrupt operations. This issue has been resolved in version 13.4.1.

Technical details

FNT Command is vulnerable to an unrestricted file upload (CWE-434) within the C Base Module. The application fails to sufficiently validate the type and content of uploaded files, allowing an authenticated attacker with low-level privileges to upload a malicious payload. By triggering the execution of the uploaded file, the attacker can achieve remote code execution (RCE) with the privileges of the application service. This can lead to a complete compromise of the server, including unauthorized data access and lateral movement within the network. The vulnerability is addressed in version 13.4.1.

Affected products

  • FNT Software Command <= 13.4.0

Timeline

  • 2024-09: disclosed: Vulnerability reported to vendor
  • 2024-10: patched: Vendor published a fix
  • 2025-12-15: advisory: NVD publication date

References

Related threats