# CVE-2024-52564

## Summary

- **CVE ID:** CVE-2024-52564
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** CWE-1242
- **Published:** Dec 5, 2024
- **Last Modified:** Mar 13, 2026

## Description

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered.

## Affected Products

- I-O DATA DEVICE, INC. — UD-LT1 (firmware Ver.2.1.8 and earlier)
- I-O DATA DEVICE, INC. — UD-LT1/EX (firmware Ver.2.1.8 and earlier)

## References

- [CNA](https://www.iodata.jp/support/information/2024/11_ud-lt1/)
- [CNA](https://jvn.jp/en/jp/JVN46615026/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 45.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._