CVE-2024-35517: Command Injection
Published Oct 11, 2024
·Updated
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usbremotesmbconf.cgi via the sharename parameter.
Affected Software
2 affected components
All of the following
Netgear Xr1000 Firmware=1.0.0.64
Netgear XR1000
Event History
Oct 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-35517?
The severity of CVE-2024-35517 has not been officially assigned a CVSS score, but it exposes the device to potential command injection attacks.
2
How do I fix CVE-2024-35517?
To fix CVE-2024-35517, update the Netgear XR1000 firmware to the latest version provided by the manufacturer.
3
What types of attacks can CVE-2024-35517 facilitate?
CVE-2024-35517 can facilitate command injection attacks through the vulnerable 'share_name' parameter.
4
Is CVE-2024-35517 remotely exploitable?
Yes, CVE-2024-35517 is remotely exploitable as it affects the web interface handling of the Netgear XR1000 router.
5
Which devices are affected by CVE-2024-35517?
CVE-2024-35517 specifically affects the Netgear XR1000 firmware version 1.0.0.64.