CVE-2024-35522
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-35522 is a vulnerability affecting the Netgear EX3700 'AC750 WiFi Range Extender Essentials Edition before version 1.0.0.98. An authenticated command injection flaw exists in the operating_mode.cgi file, which can be exploited by malicious actors through manipulation of the ap_mode parameter. This vulnerability is aggravated when ap_24g_manual is set to 1 and ap_24g_manual_sec is set to NotNone, enabling attackers to execute arbitrary commands on the system with administrative privileges. Successful exploitation may lead to unauthorized access, data theft, or system compromise. Users are advised to update their firmware to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Netgear Ex3700 Firmware
Affected Vendors
- Netgear, Inc.