CVE-2024-7120General(raisecom / msg1200)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for raisecom msg1200 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • msg1200
  • msg1200_firmware
  • msg2100e
  • msg2100e_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
msg1200msg1200_firmwaremsg2100emsg2100e_firmwaremsg2200msg2200_firmwaremsg2300msg2300_firmware

2 versions affected across 8 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-09-07: 1Active Exploitation · 2026-09-07: 1Technical Details · 2026-09-07: 102-0309-07
Signal classification2 categories
General
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-031
General1
2026-09-071
Active Exploitation1
Full discourse2 posts
  • Jason@JasonSec
    General

    @darkshadow2bd Image is of CVE-2024-7120, tips are obvious except burp collab which is just preference.

    Post summary

    The tweet briefly references CVE-2024-7120 and notes that tips are obvious, but it does not provide technical details, exploits, or any actionable information.

    00010281
    45 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are exploiting CVE-2024-7120 to completely bypass SSH authentication on MikroTik RouterOS devices, gaining direct administrative access to network infrastructure. Once compromised, they're creating persistent backdoor accounts and using these devices to pivot through internal networks. Runtime segmentation helps contain lateral movement when network infrastructure becomes the attack vector. #ZeroTrust #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/mikrotik-ssh-bypass-cve-2024-critical-vulnerability-september-2024

    Post summary

    Attackers are actively exploiting CVE‑2024‑7120 to bypass SSH authentication on MikroTik RouterOS, creating backdoor accounts and using the compromised devices for lateral movement.

    0000050
    2.0K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
HWraisecommsg1200---
OSraisecommsg1200_firmware3.90--
HWraisecommsg2100e---
OSraisecommsg2100e_firmware3.90--
HWraisecommsg2200---
OSraisecommsg2200_firmware3.90--
HWraisecommsg2300---
OSraisecommsg2300_firmware3.90--

Explore more