Command Injection Vulnerability in Netgear R8500 Router
CVE-2024-50999

Currently unrated

Key Information:

Vendor
Netgear
Vendor
CVE Published:
5 November 2024

Summary

The Netgear R8500 router version 1.0.2.160 has a command injection vulnerability in the sysNewPasswd parameter of the password.cgi script. This flaw enables attackers to craft specific requests that can lead to the execution of arbitrary operating system commands. By exploiting this vulnerability, unauthorized users can gain control over the device's operating system, potentially compromising the integrity and confidentiality of the network.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.