CVE-2024-54803

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 22, 2025
CWE ID 94

Summary

CVE-2024-54803 is a command injection vulnerability affecting the Netgear WNR854T 1.5.2 (North America) router. An attacker can exploit this issue by crafting a malicious request to the post.cgi file, resulting in an update of the nvram parameter pppoe_peer_mac. This manipulation triggers a reboot, providing the attacker with an opportunity to inject and execute arbitrary commands on the system. Successful exploitation of this vulnerability can lead to unauthorized access, data theft, or denial of service. Users are advised to update their routers as soon as a patch is released to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share