CVE-2024-35519: Command Injection
Published Oct 14, 2024
·Updated
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operatingmode.cgi via the apmode parameter.
Affected Software
6 affected components
All of the following
Netgear Ex3700 Firmware<=1.0.0.96
Netgear EX3700
All of the following
Netgear Ex6100 Firmware<=1.0.2.28
Netgear EX6100
All of the following
Netgear Ex6120 Firmware<=1.0.0.68
Netgear EX6120
Event History
Oct 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-35519?
CVE-2024-35519 has a high severity due to its potential for command injection vulnerabilities.
2
How do I fix CVE-2024-35519?
To fix CVE-2024-35519, update the firmware of affected Netgear devices to their latest versions.
3
Which Netgear devices are affected by CVE-2024-35519?
CVE-2024-35519 affects Netgear EX3700, EX6100, and EX6120 devices with specific firmware versions.
4
What is command injection in relation to CVE-2024-35519?
In CVE-2024-35519, command injection allows an attacker to execute arbitrary commands on the device through the ap_mode parameter.
5
Can CVE-2024-35519 be exploited remotely?
Yes, CVE-2024-35519 can potentially be exploited remotely by sending crafted requests to the affected devices.