- Description
- NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- netalertx
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@mitre.org
- CWE-306
- Hype score
- Not currently trending
CVE-2024-46506 NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication req… https://t.co/9wzGnWykwp
@CVEnew
13 May 2025
145 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2024-46506
@transilienceai
26 Feb 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Our latest @metasploit weekly wrap up details a new module for an unauthenticated remote code execution bug in NetAlertX (CVE-2024-46506 plus more... https://t.co/yAdr37ONSp #infosec #cybersecurity
@Raj_Samani
24 Feb 2025
85 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-46506
@transilienceai
19 Feb 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-46506
@transilienceai
10 Feb 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-46506
@transilienceai
6 Feb 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-46506
@transilienceai
5 Feb 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2024-46506: Unauthenticated RCE in NetAlertx - Rhino Security Labs https://t.co/z20tLvm4t5
@tbbhunter
31 Jan 2025
937 Impressions
1 Retweet
9 Likes
3 Bookmarks
1 Reply
0 Quotes
CVE-2024-46506: Unauthenticated RCE in NetAlertx https://t.co/FlgC6VCOuq https://t.co/ocZ7TxBsVO
@secharvesterx
30 Jan 2025
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-46506: Unauthenticated RCE in NetAlertx https://t.co/tewfa4N5q1
@_r_netsec
30 Jan 2025
613 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1A0F056B-1131-4BB9-892D-08FECBD0852F",
"versionEndExcluding": "24.10.12",
"versionStartIncluding": "23.01.14",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]