CVE-2024-6646
Last modified
CVE-2024-6646 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. EPSS estimates a 45.96% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-6646?
How severe is CVE-2024-6646?
How do I fix CVE-2024-6646?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6640In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When…6.3
- CVE-2024-6641The WP Hardening – Fix Your WordPress Security plugin for Wo…5.3
- CVE-2024-6642Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-6643Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-6644A vulnerability was found in zmops ArgusDBM up to 0.1.0. It …6.3
- CVE-2024-6645A vulnerability was found in WuKongOpenSource Wukong_nocode …6.3
- CVE-2024-6647** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified a…5.1
- CVE-2024-6648Absolute Path Traversal vulnerability in AP Page Builder ver…7.5
- CVE-2024-6649A vulnerability has been found in SourceCodester Employee an…6.5
- CVE-2024-6650A vulnerability was found in SourceCodester Employee and Vis…4.8
- CVE-2024-6651The WordPress File Upload WordPress plugin before 4.24.8 doe…6.1
- CVE-2024-6652A vulnerability was found in itsourcecode Gym Management Sys…8.8
Are you affected by CVE-2024-6646?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
