CVE-2024-54807

CWE-94Code Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
5.7%
top 9.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 31

Description

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2024-54807: In Netgear WNR854T 12025-03-31
GHSA
GHSA-8w2m-3cmp-47gw: In Netgear WNR854T 12025-03-31
CVE-2024-54807 (CRITICAL CVSS 9.8) | In Netgear WNR854T 1.5.2 (North Ame | cvebase.io