CVE-2024-35517

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Oct 11, 2024
Updated: Mar 13, 2025
CWE ID 77

Summary

CVE-2024-35517 is a newly identified vulnerability affecting the Netgear XR1000 v1.0.0.64. This issue permits command injection through the share_name parameter in the usb_remote_smb_conf.cgi file. An attacker can exploit this weakness by crafting a maliciously crafted share name and sending it to the affected device, ultimately gaining unauthorized control over it. This could potentially lead to serious consequences, such as data theft, unauthorized access, or system damage. Users are strongly advised to update their Netgear XR1000 firmware as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share