CVE-2024-5246

HIGH

NETGEAR ProSAFE Network Management Software 300 - Authenticated Remote Code Execution via Apache Tomcat

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-5246. PoCs published by Abdurahmon3236.

AI-analyzed exploit summary This PoC exploits a Remote Code Execution (RCE) vulnerability in NETGEAR ProSAFE Network Management System by deploying a malicious web application via Apache Tomcat Manager. The payload executes arbitrary PHP code, demonstrating the vulnerability.

Description

NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Apache Tomcat. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-22868.

Exploits (1)

nomisec WORKING POC 2 stars
by Abdurahmon3236 · poc
https://github.com/Abdurahmon3236/CVE-2024-5246

This PoC exploits a Remote Code Execution (RCE) vulnerability in NETGEAR ProSAFE Network Management System by deploying a malicious web application via Apache Tomcat Manager. The payload executes arbitrary PHP code, demonstrating the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NETGEAR ProSAFE Network Management System (with vulnerable Apache Tomcat)
Auth required
Prerequisites: Valid Tomcat Manager credentials · Access to Tomcat Manager interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.3130
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
netgear/prosafe_network_management_software_300 1.7.0.37
Published May 23, 2024
Tracked Since Feb 18, 2026