Vulnerability record · CVE-2024-30568 · published 3 April 2024
CVE-2024-30568: Netgear R6850 router command injection via c4-IPAddr parameter
Netgear · R6850 Firmware
Netgear R6850 firmware 1.1.0.88 contains a command injection flaw reachable through the c4-IPAddr parameter. A remote, unauthenticated attacker can inject OS commands, and the vendor has published a security advisory page. The record does not state which firmware release fixes it.
Description
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network, unauthenticated, no-interaction command execution plus a public exploit and very high EPSS percentile.
What it is
Netgear R6850 firmware 1.1.0.88 contains a command injection flaw reachable through the c4-IPAddr parameter. A remote, unauthenticated attacker can inject OS commands, and the vendor has published a security advisory page. The record does not state which firmware release fixes it.
Impact
Successful exploitation gives the attacker arbitrary command execution on the router, leading to full compromise of confidentiality, integrity and availability of the device.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction, so the vulnerable parameter is exposed over the network without authentication. The description does not specify which service or interface hosts the parameter.
Exploitation
Not listed in CISA KEV, but EPSS is 0.46918 (98.8th percentile) and the references include a public exploit write-up, indicating meaningful and elevated exploitation likelihood.
What to do
- Apply the fixed firmware from Netgear's security advisory page for the R6850; the record does not name a fixed version, so confirm with the vendor.
- If no fix is available, restrict management and WAN-facing access to the device and place it behind a firewall that blocks untrusted traffic to its web interface.
- Disable remote administration and UPnP on the router where not strictly required.
- Replace end-of-support units that will not receive firmware updates.
- Monitor the vendor advisory page for updated guidance.
Detection
- Inspect router and upstream logs for requests containing shell metacharacters in the c4-IPAddr parameter.
- Alert on unexpected outbound connections or processes spawned by the router's web service.
- Watch for configuration changes or new admin accounts on the device.
- Baseline normal traffic to the router's management interface and flag anomalous POST requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28p | ExploitThird Party Advisory |
| https://www.netgear.com/about/security/ | Vendor Advisory |
| https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28p | ExploitThird Party Advisory |
| https://www.netgear.com/about/security/ | Vendor Advisory |
Track CVE-2024-30568 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-30568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.