CVE-2024-35519

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Oct 14, 2024
Updated: Mar 17, 2025
CWE ID 78
CWE ID 77

Summary

CVE-2024-35519 is a newly identified vulnerability affecting Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 routers. The issue stems from a command injection vulnerability in the operating_mode.cgi file, which can be exploited through the ap_mode parameter. Successful exploitation enables attackers to execute arbitrary commands on the affected device, leading to potential unauthorized access, data theft, or router manipulation. Users are advised to update their routers to the latest firmware as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Netgear Ex6100 Firmware
  • Netgear Ex3700 Firmware
  • Netgear Ex6120 Firmware

Affected Vendors

  • Netgear, Inc.