CVE-2024-54802
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-54802 is a newly identified vulnerability affecting the Netgear WNR854T 1.5.2 router in North America. The issue lies in the UPnP service (upnp process located at /usr/sbin/) which is susceptible to a stack-based buffer overflow. An attacker can exploit this flaw by manipulating the M-SEARCH Host header during a specially crafted UPnP message, potentially gaining unauthorized control over the affected device. Successful exploitation could lead to remote code execution or denial of service. Users are urged to apply patches or updates as soon as they become available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Netgear, Inc.