Command Injection Vulnerability in Netgear R8500 Router
CVE-2024-50999
Currently unrated
Summary
The Netgear R8500 router version 1.0.2.160 has a command injection vulnerability in the sysNewPasswd parameter of the password.cgi script. This flaw enables attackers to craft specific requests that can lead to the execution of arbitrary operating system commands. By exploiting this vulnerability, unauthorized users can gain control over the device's operating system, potentially compromising the integrity and confidentiality of the network.
References
Timeline
Vulnerability published
Vulnerability Reserved