PT-2024-35076 · Arris · Arris Vap2500

H0E4A0R1T

·

Published

2024-05-22

·

Updated

2025-10-14

·

CVE-2024-5196

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arris VAP2500 version 08.50
Description A critical issue has been discovered, affecting an unknown part of the file /tools command.php. The manipulation of the cmb header/txt command argument leads to command injection. It is possible to initiate the attack remotely.
Recommendations For Arris VAP2500 version 08.50, consider restricting access to the /tools command.php file until a patch is available. As a temporary workaround, avoid using the cmb header/txt command argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5196

Affected Products

Arris Vap2500