CVE-2024-25851: Command Injection
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the configsequence parameter in otherpara of cgitest.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Mitigate the command injection by ensuring the cgitest.cgi config_sequence parameter used in other_para is not accepted/processed in a way that allows command execution (apply the vendor-recommended input handling for this parameter).
cgitest.cgi (Netis WF2780) config_sequence parameter (other_para) = disable/mitigate command injection via config_sequence parameter in other_para
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25851?
CVE-2024-25851 is classified as a high severity vulnerability due to its command injection capability.
How do I fix CVE-2024-25851?
To fix CVE-2024-25851, update your Netis WF2780 device to the latest firmware version released by Netis.
What specific component does CVE-2024-25851 affect?
CVE-2024-25851 affects the cgitest.cgi component of the Netis WF2780 router.
Can CVE-2024-25851 be exploited remotely?
Yes, CVE-2024-25851 can be exploited remotely if the attacker has access to the network.
What are the potential impacts of exploiting CVE-2024-25851?
Exploiting CVE-2024-25851 could allow an attacker to execute arbitrary commands on the affected Netis WF2780 device.