PatchSiren cyber security CVE debrief
CVE-2024-21846 Electrolink CVE debrief
CVE-2024-21846 is a medium-severity vulnerability affecting Electrolink FM/DAB/TV transmitters, published on April 16, 2024. An unauthenticated attacker can trigger a denial-of-service condition by sending a specially-crafted GET request to the command.cgi gateway, causing the board to reset and stopping transmitter operations. The vulnerability impacts 24 Electrolink transmitter models across DAB, FM, and TV product lines, including compact, medium, high-power, and modular variants ranging from 10W to 40kW output. CISA published advisory ICSA-24-107-02 on the same date as the CVE publication. Electrolink has not responded to CISA's requests to collaborate on mitigation; users are advised to contact Electrolink directly for additional information. The CVSS 3.1 score of 5.3 reflects network accessibility, low attack complexity, no required privileges or user interaction, and low availability impact with no confidentiality or integrity impact.
- Vendor
- Electrolink
- Product
- 10W Compact DAB Transmitter
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-16
- Original CVE updated
- 2024-04-16
- Advisory published
- 2024-04-16
- Advisory updated
- 2024-04-16
Who should care
Broadcast operators, critical infrastructure providers using Electrolink transmission equipment, media companies, telecommunications providers, and security teams responsible for OT/ICS environments in broadcast transmission facilities
Technical summary
The vulnerability exists in the command.cgi gateway of Electrolink FM/DAB/TV transmitters. An unauthenticated remote attacker can send a specially-crafted HTTP GET request to this endpoint to trigger a board reset, resulting in immediate cessation of transmitter operations. The attack requires no authentication, no user interaction, and can be executed from the network with low complexity. All 24 affected product variants across DAB, FM, and TV transmitter lines are impacted regardless of firmware version (vers:all/*). The vulnerability represents a single-point-of-failure risk for broadcast operations where these transmitters are deployed.
Defensive priority
medium
Recommended defensive actions
- Contact Electrolink directly for product-specific mitigation guidance, as the vendor has not provided patches or workarounds through CISA coordination
- Restrict network access to Electrolink transmitter management interfaces, particularly the command.cgi gateway, to trusted administrative hosts only
- Monitor for unexpected board resets or transmitter operation stops that may indicate exploitation attempts
- Implement network segmentation to isolate transmitter management interfaces from untrusted networks
- Apply CISA ICS recommended practices for defense-in-depth strategies for industrial control systems
- Review and apply cybersecurity best practices for industrial control systems from CISA guidance
Evidence notes
Vulnerability description and affected product list derived from CISA CSAF advisory ICSA-24-107-02. Vendor non-response status confirmed in remediation section of source advisory. CVSS vector and score from official CISA CSAF data.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-21846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-21846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-21846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-21846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.