CVE-2024-28005

moderate-risk
Published 2024-03-28

Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker who has obtained high privileges can execute arbitrary scripts.

Do I need to act?

-
0.41% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.7/10 Medium
NETWORK / LOW complexity

Affected Products (20)

Aterm Wr8750N Firmware
Aterm Wr8160N Firmware
Aterm Wr9500N Firmware
Aterm Wr8600N Firmware
Aterm Wr8370N Firmware
Aterm Wr8170N Firmware
Aterm Wr8700N Firmware
Aterm Wr8300N Firmware
Aterm Wr8150N Firmware
Aterm Wr4100N Firmware
Aterm Wr4500N Firmware
Aterm Wr8100N Firmware
Aterm Wr8500N Firmware
Aterm Cr2500P Firmware
Aterm Wr8400N Firmware
Aterm Wr8200N Firmware
Aterm Wr1200H Firmware
Aterm Wr7870S Firmware
Aterm Wr6670S Firmware
Aterm Wg1800Hp4 Firmware

Affected Vendors

Nec
48
/ 100
moderate-risk
Severity 19/34 · Moderate
Exploitability 2/34 · Minimal
Exposure 27/34 · High