PT-2025-13831 · NetGear · Netgear Wnr854T

Published

2024-11-16

·

Updated

2025-03-31

·

CVE-2024-54808

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netgear WNR854T version 1.5.2
Description The issue is a stack-based buffer overflow due to an unconstrained use of sscanf in the SetDefaultConnectionService function. This allows for control of the program counter and can be used to achieve arbitrary code execution.
Recommendations For Netgear WNR854T version 1.5.2, as a temporary workaround, consider disabling the SetDefaultConnectionService function until a patch is available.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03668
CVE-2024-54808

Affected Products

Netgear Wnr854T