Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netgear
Netgear wnr854t Netgear wnr854t Firmware |
|
CPEs | cpe:2.3:h:netgear:wnr854t:-:*:*:*:*:*:*:* cpe:2.3:o:netgear:wnr854t_firmware:1.5.2:*:*:*:*:*:*:* |
|
Vendors & Products |
Netgear
Netgear wnr854t Netgear wnr854t Firmware |
Wed, 02 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Apr 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-121 | |
Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-02T13:57:20.705Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-54808

Updated: 2025-04-02T13:57:14.517Z

Status : Analyzed
Published: 2025-03-31T21:15:48.310
Modified: 2025-04-17T12:55:22.040
Link: CVE-2024-54808

No data.