We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-54807



Description

In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.

Reserved 2024-12-06 | Published 2025-03-31 | Updated 2025-04-02 | Assigner mitre

References

faultpoint.com/...2025-03-25-8-cves-on-the-wnr854t-junkyard/

cve.org (CVE-2024-54807)

nvd.nist.gov (CVE-2024-54807)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-54807

Support options

Helpdesk Chat, Email, Knowledgebase