VYPR

Wnr854t Firmware

by Netgear

CVEs (6)

  • CVE-2024-54809CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an…

  • CVE-2024-54808CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code…

  • CVE-2024-54806CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

  • CVE-2024-54805CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to…

  • CVE-2024-54803CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

  • CVE-2017-18855HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR WNR854T devices before 1.5.2 are affected by command execution.