CVE-2024-52025: Medium severity netgear nms300 firmware vulnerability
Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoelocalip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52025?
CVE-2024-52025 is categorized as a medium severity vulnerability due to its potential to cause a Denial of Service.
How do I fix CVE-2024-52025?
To fix CVE-2024-52025, update your Netgear XR300, R7000P, or R6400 router to the latest firmware version provided by Netgear.
Who is affected by CVE-2024-52025?
CVE-2024-52025 affects users of Netgear XR300, R7000P, and R6400 routers running specific versions of their firmware.
What can happen if CVE-2024-52025 is exploited?
If CVE-2024-52025 is exploited, attackers can cause a Denial of Service, disrupting the router's functionality.
What specific parameter is involved in CVE-2024-52025?
CVE-2024-52025 involves a stack overflow vulnerability related to the pppoe_localip parameter in geniepppoe.cgi.