CVE-2024-46506

CRITICAL EXPLOITED NUCLEI

Unauthenticated RCE in NetAlertX

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2024-46506 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including fufu-byte, Chebuya (Rhino Security Labs), Takahiro Yokoyama, including a Metasploit module exploits/linux/http/netalertx_rce_cve_2024_46506. A Nuclei detection template is also available.

AI-analyzed exploit summary This Python script exploits CVE-2024-46506, an RCE vulnerability in NetAlertX versions 23.01.14 to 24.9.12. It abuses the settings update mechanism to inject arbitrary commands via the DBCLNP_CMD parameter and triggers execution through the task queue.

Description

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

Exploits (2)

nomisec WORKING POC
by fufu-byte · remote
https://github.com/fufu-byte/CVE-2024-46506

This Python script exploits CVE-2024-46506, an RCE vulnerability in NetAlertX versions 23.01.14 to 24.9.12. It abuses the settings update mechanism to inject arbitrary commands via the DBCLNP_CMD parameter and triggers execution through the task queue.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NetAlertX versions 23.01.14 to 24.9.12
No auth needed
Prerequisites: Network access to the target's web interface · Vulnerable version of NetAlertX
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Chebuya (Rhino Security Labs), Takahiro Yokoyama · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/netalertx_rce_cve_2024_46506.rb

This Metasploit module exploits an unauthenticated RCE vulnerability in NetAlertX by updating settings to execute arbitrary commands via the DBCLNP_CMD parameter. It leverages the application's cron job execution mechanism to trigger the payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NetAlertX versions 23.01.14 to 24.9.12
No auth needed
Prerequisites: Network access to the target's HTTP interface (port 20211 by default)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution
CRITICALVERIFIEDby s4e-io
FOFA: title="netalertx"

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.5023
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-05-13
CWE
CWE-306
Status published
Products (1)
netalertx/netalertx 23.01.14 - 24.10.12
Published May 13, 2025
Tracked Since Feb 18, 2026