First published: Mon Oct 14 2024(Updated: )
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NETGEAR EX3700 firmware | <=1.0.0.96 | |
Netgear EX3700 | ||
All of | ||
NETGEAR EX6100 firmware | <=1.0.2.28 | |
Netgear EX6100 | ||
All of | ||
NETGEAR EX6120 firmware | <=1.0.0.68 | |
Netgear EX6120 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35519 has a high severity due to its potential for command injection vulnerabilities.
To fix CVE-2024-35519, update the firmware of affected Netgear devices to their latest versions.
CVE-2024-35519 affects Netgear EX3700, EX6100, and EX6120 devices with specific firmware versions.
In CVE-2024-35519, command injection allows an attacker to execute arbitrary commands on the device through the ap_mode parameter.
Yes, CVE-2024-35519 can potentially be exploited remotely by sending crafted requests to the affected devices.