In Netgear WNR854T 1.5.2 (North America), the UPNP...
Critical severity
Unreviewed
Published
Mar 31, 2025
to the GitHub Advisory Database
•
Updated Apr 2, 2025
Description
Published by the National Vulnerability Database
Mar 31, 2025
Published to the GitHub Advisory Database
Mar 31, 2025
Last updated
Apr 2, 2025
In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted SOAPAction request for AddPortMapping via the router's WANIPConn1 service to achieve arbitrary command execution.
References