First published: Fri Oct 11 2024(Updated: )
Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NETGEAR XR1000 | =1.0.0.64 | |
NETGEAR XR1000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-35517 has not been officially assigned a CVSS score, but it exposes the device to potential command injection attacks.
To fix CVE-2024-35517, update the Netgear XR1000 firmware to the latest version provided by the manufacturer.
CVE-2024-35517 can facilitate command injection attacks through the vulnerable 'share_name' parameter.
Yes, CVE-2024-35517 is remotely exploitable as it affects the web interface handling of the Netgear XR1000 router.
CVE-2024-35517 specifically affects the Netgear XR1000 firmware version 1.0.0.64.