CVE-2024-5196: Arris VAP2500 tools_command.php command injection
Published May 22, 2024
·Updated
A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /toolscommand.php. The manipulation of the argument cmbheader/txtcommand leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265833 was assigned to this vulnerability.
Affected Software
3 affected components
Arris VAP2500
All of the following
Arris Vap2500 Firmware=08.50
Arris VAP2500
Event History
May 22, 2024
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5196?
CVE-2024-5196 is classified as a critical vulnerability.
2
How do I fix CVE-2024-5196?
To fix CVE-2024-5196, update the Arris VAP2500 to the latest firmware version provided by the manufacturer.
3
What type of vulnerability is CVE-2024-5196?
CVE-2024-5196 is a command injection vulnerability.
4
Can CVE-2024-5196 be exploited remotely?
Yes, CVE-2024-5196 can be exploited remotely.
5
Which device is affected by CVE-2024-5196?
CVE-2024-5196 affects the Arris VAP2500 device.