CVE-2024-45841: I-O Data Device, Inc Ud-LT1
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.
Affected products
- I-O Data Device, Inc Ud-LT1: up to and including 2.1.9
- I-O Data Device, Inc Ud-LT1/EX: up to and including 2.1.9
Published 2024-12-05. Last modified 2026-06-17.