CVE-2024-7731: Secom Dr.id Access Control
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Affected products
- Secom Dr.id Access Control: before 3.6.3 (fixed in 3.6.3)
Published 2024-08-14. Last modified 2026-06-17.