Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgear
Netgear wnr854t Netgear wnr854t Firmware |
|
| CPEs | cpe:2.3:h:netgear:wnr854t:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:wnr854t_firmware:1.5.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netgear
Netgear wnr854t Netgear wnr854t Firmware |
Wed, 02 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-03-31T00:00:00.000Z
Updated: 2025-04-02T13:57:20.705Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-54808
Updated: 2025-04-02T13:57:14.517Z
Status : Analyzed
Published: 2025-03-31T21:15:48.310
Modified: 2025-04-17T12:55:22.040
Link: CVE-2024-54808
No data.