cve/2024/CVE-2024-54807.md
2025-09-29 16:08:36 +00:00

922 B

CVE-2024-54807

Description

** UNSUPPORTED WHEN ASSIGNED ** In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.

POC

Reference

Github

No PoCs found on GitHub currently.