CVE-2024-4999: Ligowave Apc Propeller

Critical severity, CVSS 9.4. EPSS: 12.2% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.

Affected products

  • Ligowave Apc Propeller: up to and including 2-5.95-4.rt3352; version 2-5.95-4.rt3352 only
  • Ligowave Mimo: up to and including 6.95-1.rt2880; version 6.95-1.rt2880 only
  • Ligowave Pro: up to and including 6.95-1.rt3883; version 6.95-1.rt3883 only
  • Ligowave Unity: up to and including 6.95-2; version 6.95-2 only

Published 2024-05-16. Last modified 2026-06-17.