← All CVEs

CVE-2024-54808

critical · 9.8

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.

9.8
CVSS
0.8%
EPSS (exploit prob.)
54th
EPSS percentile
2025-03-31
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

Affected products

VendorProductAffected versions
netgearwnr854t_firmware1.5.2
netgearwnr854tall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-54808