Command Injection Vulnerability in Netgear Routers
CVE-2024-51010

Currently unrated

Key Information:

Vendor
Netgear
Vendor
CVE Published:
5 November 2024

Summary

Multiple models of Netgear routers, including R8500, XR300, R7000P, and R6400, have been identified with a command injection issue within the ap_mode.cgi handler. This weakness arises from improper validation of the apmode_gateway parameter, which can be exploited by attackers to send carefully crafted requests that execute arbitrary operating system commands. This poses a significant risk, allowing unauthorized access to the underlying system and the potential manipulation of network configurations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.