CVE-2024-35518: Command Injection
Published Oct 14, 2024
·Updated
Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in geniefix2.cgi via the wandns1pri parameter.
Affected Software
2 affected components
All of the following
Netgear Ex6120 Firmware<=1.0.0.68
Netgear EX6120
Event History
Oct 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35518?
CVE-2024-35518 is classified as a high-severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2024-35518?
To fix CVE-2024-35518, users should upgrade to a patched version of the firmware beyond v1.0.0.68.
3
Who is affected by CVE-2024-35518?
CVE-2024-35518 affects users of the Netgear EX6120 with firmware version 1.0.0.68 or lower.
4
What type of vulnerability is CVE-2024-35518?
CVE-2024-35518 is a command injection vulnerability identified in the genie_fix2.cgi script.
5
What are the potential impacts of CVE-2024-35518?
Exploitation of CVE-2024-35518 may allow an attacker to execute arbitrary commands on the vulnerable Netgear EX6120 device.