CVE-2024-30220: Planex Mzk-MF300HP2 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided.

Affected products

  • Planex Mzk-MF300HP2 Firmware: up to and including 1.18
  • Planex Mzk-MF300N Firmware: any version

Published 2024-04-15. Last modified 2026-06-17.