CVE-2024-10381: Matrixcomsec Cosec Vega Faxq Firmware

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this vulnerability could allow remote attacker to gain unauthorized access and take complete control of the targeted device.

Affected products

  • Matrixcomsec Cosec Vega Faxq Firmware: before v2r17 (fixed in v2r17)

Published 2024-10-25. Last modified 2026-06-17.