CVE-2024-4235
Last modified
CVE-2024-4235 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads to cleartext storage of sensitive information. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-262126 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Dg834gv5 Firmware | 1.6.01.34 |
References
- https://vuldb.com/?ctiid.262126Permissions Required, VDB Entry
- https://vuldb.com/?id.262126Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.319148Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.262126Permissions Required, VDB Entry
- https://vuldb.com/?id.262126Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.319148Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4235?
How severe is CVE-2024-4235?
How do I fix CVE-2024-4235?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42344A vulnerability has been identified in SINEMA Remote Connect…5.5
- CVE-2024-42345A vulnerability has been identified in SINEMA Remote Connect…4.3
- CVE-2024-42346Galaxy is a free, open-source system for analyzing data, aut…5.4
- CVE-2024-42347matrix-react-sdk is a react-based SDK for inserting a Matri…6.5
- CVE-2024-42348FOG is a cloning/imaging/rescue suite/inventory management s…8.6
- CVE-2024-42349FOG is a cloning/imaging/rescue suite/inventory management s…5.3
- CVE-2024-42350Biscuit is an authorization token with decentralized verific…3
- CVE-2024-42351Galaxy is a free, open-source system for analyzing data, aut…9.1
- CVE-2024-42352Nuxt is a free and open-source framework to create full-stac…7.5
- CVE-2024-42353WebOb provides objects for HTTP requests and responses. When…6.1
- CVE-2024-42354Shopware is an open commerce platform. The store-API works w…5.9
- CVE-2024-42355Shopware, an open ecommerce platform, has a new Twig Tag `sw…9.8
Are you affected by CVE-2024-4235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
