First published: Fri Oct 11 2024(Updated: )
Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set to 1 and ap_24g_manual_sec set to NotNone.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
NETGEAR EX3700 firmware | <1.0.0.98 | |
Netgear EX3700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35522 is classified as a high severity vulnerability due to the potential for authenticated command injection.
To fix CVE-2024-35522, update the Netgear EX3700 firmware to version 1.0.0.98 or later.
CVE-2024-35522 affects the Netgear EX3700 AC750 WiFi Range Extender Essentials Edition running firmware versions prior to 1.0.0.98.
Users of the Netgear EX3700 WiFi Range Extender with the vulnerable firmware are at risk from CVE-2024-35522.
CVE-2024-35522 can be exploited through authenticated access via the ap_mode parameter in the operating_mode.cgi script.