CVE-2024-55063: Easyvirt DC Netscope

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the (4) timezone parameter to /international/settings/timezone.

Affected products

  • Easyvirt DC Netscope: up to and including 8.7.0

Published 2025-05-19. Last modified 2026-06-17.