PT-2025-13825 · NetGear · Netgear Wnr854T

CVE-2024-54802

·

Published

2024-11-16

·

Updated

2025-04-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netgear WNR854T version 1.5.2
Description The issue concerns a stack-based buffer overflow in the M-SEARCH Host header of the UPNP service, located at /usr/sbin/upnp.
Recommendations For Netgear WNR854T version 1.5.2, consider disabling the UPNP service until a patch is available. Restrict access to the /usr/sbin/upnp service to minimize the risk of exploitation. Avoid using the M-SEARCH Host header in the affected UPNP service until the issue is resolved.

Exploit

Fix

Stack Overflow

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03667
CVE-2024-54802

Affected Products

Netgear Wnr854T