CVE-2024-48457
Last modified
CVE-2024-48457 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the endpoint /cgi-bin/skk_set.cgi and binary /bin/scripts/start_wifi.sh. EPSS estimates a 3.03% chance of exploitation in the next 30 days.
Description
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the endpoint /cgi-bin/skk_set.cgi and binary /bin/scripts/start_wifi.sh
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-48457?
How severe is CVE-2024-48457?
How do I fix CVE-2024-48457?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4845The Icegram Express plugin for WordPress is vulnerable to SQ…8.8
- CVE-2024-48450An arbitrary file upload vulnerability in Huly Platform v0.6…6.5
- CVE-2024-48453An issue in INOVANCE AM401_CPU1608TPTN allows a remote attac…9.8
- CVE-2024-48454An issue in SourceCodester Purchase Order Management System …7.2
- CVE-2024-48455An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.358…2.7
- CVE-2024-48456An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.358…7.5
- CVE-2024-48459A command execution vulnerability exists in the AX2 Pro home…7.3
- CVE-2024-4846Authentication bypass in the 2FA feature in Devolutions Serv…6.3
- CVE-2024-48460An issue in Eugeny Tabby 1.0.213 allows a remote attacker to…4.3
- CVE-2024-48461Cross Site Scripting vulnerability in TeslaLogger Admin Pane…4.8
- CVE-2024-48463Bruno before 1.29.1 uses Electron shell.openExternal without…6.5
- CVE-2024-48465The MRBS version 1.5.0 has an SQL injection vulnerability in…9.8
Are you affected by CVE-2024-48457?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
