CVE-2024-23618

CRITICAL

Arris SURFboard SBG6950AC2 Firmware - Unauthenticated Remote Code Execution

Title source: llm
STIX 2.1

Description

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.

References (1)

Core 1

Scores

CVSS v3 9.6
EPSS 0.0121
EPSS Percentile 64.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
commscope/arris_surfboard_sbg6950ac2_firmware
Published Jan 26, 2024
Tracked Since Feb 18, 2026