CVE-2024-28521: Netentsec Application Security Gateway Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.

Affected products

  • Netentsec Application Security Gateway Firmware: version 6.3.1 only

Published 2024-03-21. Last modified 2026-06-17.