OS Command Injection in Archer C4500X - CVE-2024-5035

 

OS Command Injection in Archer C4500X - CVE-2024-5035

Published: May 28, 2024


Vulnerability identifier: #VU89842
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-5035
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the "rftest" service. A remote unauthenticated attacker can send specially crafted requests to ports TCP/8888, TCP/8889, or TCP/8890 and execute arbitrary OS commands on the target device.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Archer C4500X

How to mitigate CVE-2024-5035

Install updates from vendor's website.

Archer C4500X - update to 1_1.1.7

External References

Related Security Bulletins