CVE-2024-54808

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wnr854t_firmware:1.5.2:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr854t:-:*:*:*:*:*:*:*

History

17 Apr 2025, 12:55

Type Values Removed Values Added
References () https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#808 - () https://faultpoint.com/post/2025-03-25-8-cves-on-the-wnr854t-junkyard/#808 - Exploit, Third Party Advisory
First Time Netgear
Netgear wnr854t Firmware
Netgear wnr854t
CPE cpe:2.3:o:netgear:wnr854t_firmware:1.5.2:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr854t:-:*:*:*:*:*:*:*

02 Apr 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Netgear WNR854T 1.5.2 (Norteamérica) presenta una vulnerabilidad de desbordamiento de búfer en la función SetDefaultConnectionService debido al uso sin restricciones de sscanf. Esta vulnerabilidad permite controlar el contador del programa y puede utilizarse para ejecutar código arbitrario.
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

31 Mar 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 21:15

Updated : 2025-04-17 12:55


NVD link : CVE-2024-54808

Mitre link : CVE-2024-54808

CVE.ORG link : CVE-2024-54808


JSON object : View

Products Affected

netgear

  • wnr854t_firmware
  • wnr854t
CWE
CWE-121

Stack-based Buffer Overflow