CVE-2024-46506

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/05/2025
Last modified:
17/06/2025

Description

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:* 23.01.14 (including) 24.10.12 (excluding)