CVE-2024-35519Command Injection in Netgear Ex3700 Firmware

Severity
6.8MEDIUMNVD
CNA8.4
EPSS
0.2%
top 51.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateOct 15

Description

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-6vmj-9xjc-fxmr: Netgear EX6120 v12024-10-15
CVEList
CVE-2024-35519: Netgear EX6120 v12024-10-14
CVE-2024-35519 — Command Injection in Netgear | cvebase