CVE-2024-25850
Netis-systems
CVE-2024-25850 is a critical command injection vulnerability affecting Netis WF2780 routers. This flaw allows attackers to execute arbitrary commands on the system through the wps_ap_ssid5g parameter.
CVE-2024-25850 impacts Netis WF2780 version 2.1.40144, exposing it to potential remote code execution. Though the CVSS score is high (9.8), the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower level of real-world exploitability compared to vulnerabilities with SVRS scores above 80. However, given that the CVE is tagged as "In The Wild," users of the affected Netis router should still implement security precautions and look for updates. An attacker exploiting this vulnerability could gain complete control of the vulnerable router, leading to data breaches, network compromise, or denial of service. Patching the firmware is advised to mitigate this security risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.