CVE-2024-54805

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 17, 2025
CWE ID 94

Summary

CVE-2024-54805 is a newly disclosed vulnerability affecting the Netgear WNR854T 1.5.2 (North America) router firmware. This issue allows an attacker to execute arbitrary commands through a Command Injection vulnerability in the post.cgi file. By sending a crafted request to update the nvram parameter get_email, an attacker can manipulate this input and subsequently exploit the vulnerability in send_log.cgi. This endpoint uses the malicious input in a system call, enabling the attacker to execute commands with administrative privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share