PoC Index

CVE-2024-54808

CRITICAL 9.8EPSS 0.8%

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.77% chance of exploitation in the next 30 days, 53th percentile
Published
2025-03-31
Updated
2025-04-02

Proof-of-concept exploits (1)

References

Related