PatchSiren cyber security CVE debrief
CVE-2024-1491 Electrolink CVE debrief
A critical unauthenticated file upload vulnerability affects 24 Electrolink FM/DAB/TV transmitter models. The devices expose an unprotected endpoint allowing MPFS (Microchip Proprietary File System) binary image uploads without authentication. An attacker can exploit this to overwrite flash program memory containing the web server's main interfaces, leading to arbitrary code execution. The vulnerability stems from the MPFS2 file system module, which provides read-only storage for the HTTP2 web server and SNMP modules but can be abused to modify internal flash memory. Electrolink has not responded to CISA coordination requests, leaving affected users without vendor-provided mitigations. The broad product coverage across DAB, FM, and TV transmitter lines with all versions affected indicates extensive exposure in broadcast infrastructure environments.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast station engineers, critical infrastructure security teams, OT/ICS security practitioners, telecommunications regulators, and organizations operating Electrolink transmission equipment
Technical summary
The vulnerability exists in the MPFS2 file system upload endpoint, which lacks authentication controls. The MPFS2 module normally provides read-only file system capabilities stored in external EEPROM, serial flash, or internal program memory for the HTTP2 web server and SNMP modules. However, the exposed upload endpoint allows attackers to write arbitrary binary images, overwriting the flash program memory that contains the web server's main interfaces. This enables code execution within the transmitter's embedded system. The attack is network-accessible without credentials, requires no user interaction, and affects all versions of 24 distinct transmitter products spanning DAB, FM, and TV broadcast equipment.
Defensive priority
HIGH
Recommended defensive actions
- Contact Electrolink directly for security updates or mitigation guidance, as the vendor has not coordinated with CISA on fixes
- Restrict network access to affected transmitter management interfaces using firewall rules or network segmentation
- Monitor for unauthorized MPFS upload attempts to the unprotected endpoint
- Implement defense-in-depth controls per CISA ICS recommended practices for industrial control systems
- Consider disabling remote management interfaces if not operationally required
- Review and apply CISA ICS-CERT defense in depth guidance for protecting critical broadcast infrastructure
Evidence notes
Vulnerability description and affected product list derived from CISA ICS Advisory ICSA-24-107-02. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N confirms network-exploitable, unauthenticated attack with high integrity impact. Vendor non-response status documented in advisory remediations section.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-1491 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-1491
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-1491 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-1491
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.