CVE-2024-25850: Command Injection
Published Feb 22, 2024
·Updated
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wpsapssid5g parameter
Affected Software
3 affected components
Netis WF2780
All of the following
netis-systems Wf2780 Firmware=2.1.40144
netis-systems Wf2780
Event History
Feb 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25850?
CVE-2024-25850 has been classified with a medium severity due to its command injection potential.
2
How do I fix CVE-2024-25850?
To fix CVE-2024-25850, update the Netis WF2780 firmware to the latest version provided by the vendor.
3
What systems are affected by CVE-2024-25850?
CVE-2024-25850 affects the Netis WF2780 router running firmware version 2.1.40144.
4
What type of vulnerability is CVE-2024-25850?
CVE-2024-25850 is a command injection vulnerability that allows attackers to execute arbitrary commands.
5
Can CVE-2024-25850 be exploited remotely?
Yes, CVE-2024-25850 can potentially be exploited remotely if the vulnerable parameter is accessed externally.