PT-2025-13825 · NetGear · Netgear Wnr854T
CVE-2024-54802
·
Published
2024-11-16
·
Updated
2025-04-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netgear WNR854T version 1.5.2
Description
The issue concerns a stack-based buffer overflow in the M-SEARCH Host header of the UPNP service, located at
/usr/sbin/upnp.Recommendations
For Netgear WNR854T version 1.5.2, consider disabling the UPNP service until a patch is available. Restrict access to the
/usr/sbin/upnp service to minimize the risk of exploitation. Avoid using the M-SEARCH Host header in the affected UPNP service until the issue is resolved.Exploit
Fix
Stack Overflow
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear Wnr854T