CVE-2024-5194

A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assoc_table.php. The manipulation of the argument id leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265831.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:arris:vap2500_firmware:08.50:*:*:*:*:*:*:*
cpe:2.3:h:arris:vap2500:-:*:*:*:*:*:*:*

History

14 Oct 2025, 19:30

Type Values Removed Values Added
CPE cpe:2.3:h:arris:vap2500:-:*:*:*:*:*:*:*
cpe:2.3:o:arris:vap2500_firmware:08.50:*:*:*:*:*:*:*
References () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/a%2B%26%5BE4%3Flp5%3Fk9_%3D%5D/ARRIS_VAP2500-RCE-assoc_table.php.pdf - () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/a%2B%26%5BE4%3Flp5%3Fk9_%3D%5D/ARRIS_VAP2500-RCE-assoc_table.php.pdf - Broken Link
References () https://vuldb.com/?ctiid.265831 - () https://vuldb.com/?ctiid.265831 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.265831 - () https://vuldb.com/?id.265831 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.335252 - () https://vuldb.com/?submit.335252 - Third Party Advisory, VDB Entry
First Time Arris vap2500 Firmware
Arris vap2500
Arris

Information

Published : 2024-05-22 11:15

Updated : 2025-10-14 19:30


NVD link : CVE-2024-5194

Mitre link : CVE-2024-5194

CVE.ORG link : CVE-2024-5194


JSON object : View

Products Affected

arris

  • vap2500
  • vap2500_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')