First published: Tue Nov 05 2024(Updated: )
Netgear R7000P v1.3.3.154 was discovered to contain a command injection vulnerability via the device_name2 parameter at operation_mode.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51015 is considered a high severity vulnerability due to its potential for command injection.
To fix CVE-2024-51015, update the Netgear R7000P router firmware to the latest version provided by Netgear.
CVE-2024-51015 allows attackers to execute arbitrary OS commands, potentially compromising the device and network.
Users of the Netgear R7000P running firmware version v1.3.3.154 are specifically affected by CVE-2024-51015.
Attackers can exploit CVE-2024-51015 by sending a crafted request that manipulates the device_name2 parameter in operation_mode.cgi.