Netgear EX6120 v1.0.0.68 vulnerable to Command Injection
CVE-2024-35518
6.8MEDIUM
Summary
The Netgear EX6120 (version 1.0.0.68) is susceptible to a Command Injection vulnerability within the genie_fix2.cgi script. This flaw allows attackers to exploit the wan_dns1_pri parameter, potentially leading to unauthorized command execution on the device. Effective mitigation and awareness are essential to safeguard against potential attacks targeting this vulnerability.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published