CVE-2024-50707: Uniguest Tripleplay

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.

Affected products

  • Uniguest Tripleplay: before 24.1.2 (fixed in 24.1.2); version 24.2 only

Published 2025-03-04. Last modified 2026-06-17.