CVE-2024-54803
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-54803 is a command injection vulnerability affecting the Netgear WNR854T 1.5.2 (North America) router. An attacker can exploit this issue by crafting a malicious request to the post.cgi file, resulting in an update of the nvram parameter pppoe_peer_mac. This manipulation triggers a reboot, providing the attacker with an opportunity to inject and execute arbitrary commands on the system. Successful exploitation of this vulnerability can lead to unauthorized access, data theft, or denial of service. Users are advised to update their routers as soon as a patch is released to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Netgear, Inc.