CVE-2024-52024: Medium severity netgear nms300 firmware vulnerability
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoelocalip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52024?
CVE-2024-52024 has been classified as a high severity vulnerability due to its potential to cause a Denial of Service (DoS).
How do I fix CVE-2024-52024?
To mitigate CVE-2024-52024, update the firmware of affected Netgear devices to the latest version provided by Netgear.
Which devices are affected by CVE-2024-52024?
CVE-2024-52024 affects Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128.
What type of attack does CVE-2024-52024 enable?
CVE-2024-52024 enables attackers to perform a Denial of Service (DoS) by exploiting a stack overflow vulnerability.
What is the vulnerable parameter in CVE-2024-52024?
The vulnerability in CVE-2024-52024 is related to the 'pppoe_localip' parameter in the 'wizpppoe.cgi' script.