CVE-2024-35520: Command Injection
Published Oct 14, 2024
·Updated
Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMTinvite.cgi via devicename2 parameter.
Affected Software
2 affected components
All of the following
Netgear R7000 Firmware=1.0.11.136
Netgear R7000
Event History
Oct 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35520?
CVE-2024-35520 is rated as a high severity vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2024-35520?
To fix CVE-2024-35520, update your Netgear R7000 firmware to the latest version released by Netgear.
3
What type of vulnerability is CVE-2024-35520?
CVE-2024-35520 is classified as a command injection vulnerability affecting the RMT_invite.cgi script.
4
Which devices are affected by CVE-2024-35520?
CVE-2024-35520 specifically affects Netgear R7000 devices running firmware version 1.0.11.136.
5
Could CVE-2024-35520 lead to complete system compromise?
Yes, CVE-2024-35520 could allow an attacker to execute arbitrary commands on the affected device, potentially leading to full system compromise.