CVE-2024-30572

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:r6850_firmware:1.1.0.88:*:*:*:*:*:*:*
cpe:2.3:h:netgear:r6850:-:*:*:*:*:*:*:*

History

04 Apr 2025, 16:32

Type Values Removed Values Added
References () https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28ntp_server%29.md - () https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28ntp_server%29.md - Exploit, Third Party Advisory
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory
First Time Netgear r6850
Netgear
Netgear r6850 Firmware
CPE cpe:2.3:h:netgear:r6850:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:r6850_firmware:1.1.0.88:*:*:*:*:*:*:*

13 Mar 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-77

Information

Published : 2024-04-03 13:16

Updated : 2025-04-04 16:32


NVD link : CVE-2024-30572

Mitre link : CVE-2024-30572

CVE.ORG link : CVE-2024-30572


JSON object : View

Products Affected

netgear

  • r6850
  • r6850_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')