CVE-2024-46506

Published May 13, 2025

Last updated 9 months ago

Overview

Description
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.
Source
cve@mitre.org
NVD status
Analyzed
Products
netalertx

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-306

Social media

Hype score
Not currently trending
  1. CVE-2024-46506 NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication req… https://t.co/9wzGnWykwp

    @CVEnew

    13 May 2025

    145 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2024-46506

    @transilienceai

    26 Feb 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Our latest @metasploit weekly wrap up details a new module for an unauthenticated remote code execution bug in NetAlertX (CVE-2024-46506 plus more... https://t.co/yAdr37ONSp #infosec #cybersecurity

    @Raj_Samani

    24 Feb 2025

    85 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Actively exploited CVE : CVE-2024-46506

    @transilienceai

    19 Feb 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2024-46506

    @transilienceai

    10 Feb 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2024-46506

    @transilienceai

    6 Feb 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2024-46506

    @transilienceai

    5 Feb 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. CVE-2024-46506: Unauthenticated RCE in NetAlertx - Rhino Security Labs https://t.co/z20tLvm4t5

    @tbbhunter

    31 Jan 2025

    937 Impressions

    1 Retweet

    9 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  9. CVE-2024-46506: Unauthenticated RCE in NetAlertx https://t.co/FlgC6VCOuq https://t.co/ocZ7TxBsVO

    @secharvesterx

    30 Jan 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-46506: Unauthenticated RCE in NetAlertx https://t.co/tewfa4N5q1

    @_r_netsec

    30 Jan 2025

    613 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations