CVE-2024-3741: Electrolink Compact Dab Transmitter

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.

Affected products

  • Electrolink Compact Dab Transmitter: version 10W only; version 100W only; version 250W only
  • Electrolink Compact Fm Transmitter: version 500W only; version 1kW only; version 2kW only
  • Electrolink Digital Fm Transmitter: from 15W, up to and including 40kW; version 15W only
  • Electrolink High Power Dab Transmitter: version 2.5kW only; version 3kW only; version 4kW only; version 5kW only
  • Electrolink Medium Dab Transmitter: version 500W only; version 1kW only; version 2kW only
  • Electrolink Modular Fm Transmitter: version 3kW only; version 5kW only; version 10kW only; version 15kW only; version 20kW only; version 30kW only
  • Electrolink Uhf Tv Transmitter: from 10W, up to and including 5kW; version 10W only
  • Electrolink Vhf Tv Transmitter

Published 2024-04-18. Last modified 2026-06-17.