VYPR
Unrated severityNVD Advisory· Published May 13, 2025· Updated May 13, 2025

CVE-2024-46506

CVE-2024-46506

Description

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

Affected products

2
  • Range: >=23.01.14, <24.10.12
  • NetAlertX/NetAlertXv5
    Range: 23.01.14

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.