S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 27, 2025

CVE-2024-30568 Scanner

CVE-2024-30568 Scanner - Command Injection vulnerability in Netgear R6850 Router

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-30568
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
r6850_firmwareby netgear
1.1.0.88
Updated Sep 10, 2026View on NVD →
Detail

The Netgear R6850 Router is widely used in residential and small office settings as it provides connectivity options for various devices. It is manufactured by Netgear, a global networking company known for delivering innovative networking solutions. Designed to support seamless internet access, this router often serves as a critical component of local networks. The R6850 model is valued for its reliability and ease of configuration, making it popular among non-technical users. It features wireless and ethernet connections, ensuring versatility across different network environments.

However, the R6850 router contains a significant command injection vulnerability. This vulnerability allows unauthorized users to inject and execute arbitrary system commands. It is specifically present in the 'ping_test' functionality, exploitable through the c4_IPAddr parameter. This issue poses a severe security risk as it enables remote code execution with root-level privileges.

Technical analysis has identified the c4_IPAddr parameter of the ping_test function as the vulnerable endpoint. Attackers can craft special requests to exploit this vulnerability, with the potential to control and manipulate the command line interface. The vulnerability supports command chaining, allowing for extensive and unrestricted command execution. Successful exploitation requires no authentication, significantly increasing the risk factor associated with the router.

When exploited, the command injection vulnerability could have severe consequences. Attackers could deliver and execute malicious software, deploy backdrops, capture sensitive data, or entirely disrupt router operations. Such exploitation might lead to unauthorized network access, anonymity compromise, and additional propagation of malware within the connected network.

REFERENCES

Solution Advice
  • Regularly check for and install firmware updates from Netgear to patch vulnerabilities.
  • Implement network segmentation to limit access to the router's management interface.
  • Use strong, unique passwords to protect router settings.
  • Disable services and ports that are not necessary for your network usage.
  • Consider implementing additional security layers, such as firewalls and intrusion detection systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-30568 Scanner - Command Injection vulnerability in Netgear R6850 Router | S4E