PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-21846 Electrolink CVE debrief

CVE-2024-21846 is a medium-severity vulnerability affecting Electrolink FM/DAB/TV transmitters, published on April 16, 2024. An unauthenticated attacker can trigger a denial-of-service condition by sending a specially-crafted GET request to the command.cgi gateway, causing the board to reset and stopping transmitter operations. The vulnerability impacts 24 Electrolink transmitter models across DAB, FM, and TV product lines, including compact, medium, high-power, and modular variants ranging from 10W to 40kW output. CISA published advisory ICSA-24-107-02 on the same date as the CVE publication. Electrolink has not responded to CISA's requests to collaborate on mitigation; users are advised to contact Electrolink directly for additional information. The CVSS 3.1 score of 5.3 reflects network accessibility, low attack complexity, no required privileges or user interaction, and low availability impact with no confidentiality or integrity impact.

Vendor
Electrolink
Product
10W Compact DAB Transmitter
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-16
Original CVE updated
2024-04-16
Advisory published
2024-04-16
Advisory updated
2024-04-16

Who should care

Broadcast operators, critical infrastructure providers using Electrolink transmission equipment, media companies, telecommunications providers, and security teams responsible for OT/ICS environments in broadcast transmission facilities

Technical summary

The vulnerability exists in the command.cgi gateway of Electrolink FM/DAB/TV transmitters. An unauthenticated remote attacker can send a specially-crafted HTTP GET request to this endpoint to trigger a board reset, resulting in immediate cessation of transmitter operations. The attack requires no authentication, no user interaction, and can be executed from the network with low complexity. All 24 affected product variants across DAB, FM, and TV transmitter lines are impacted regardless of firmware version (vers:all/*). The vulnerability represents a single-point-of-failure risk for broadcast operations where these transmitters are deployed.

Defensive priority

medium

Recommended defensive actions

  • Contact Electrolink directly for product-specific mitigation guidance, as the vendor has not provided patches or workarounds through CISA coordination
  • Restrict network access to Electrolink transmitter management interfaces, particularly the command.cgi gateway, to trusted administrative hosts only
  • Monitor for unexpected board resets or transmitter operation stops that may indicate exploitation attempts
  • Implement network segmentation to isolate transmitter management interfaces from untrusted networks
  • Apply CISA ICS recommended practices for defense-in-depth strategies for industrial control systems
  • Review and apply cybersecurity best practices for industrial control systems from CISA guidance

Evidence notes

Vulnerability description and affected product list derived from CISA CSAF advisory ICSA-24-107-02. Vendor non-response status confirmed in remediation section of source advisory. CVSS vector and score from official CISA CSAF data.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-21846 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-21846

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-21846 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-21846

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-107-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-107-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.