Vulnerability record · CVE-2024-5505 · published 6 June 2024
CVE-2024-5505: NETGEAR ProSAFE NMS UpLoadServlet path traversal leads to RCE
Netgear · Prosafe Network Management System
The UpLoadServlet class in NETGEAR ProSAFE Network Management System fails to validate a user-supplied path before using it in file operations, allowing directory traversal. Because the traversed path feeds file handling, an authenticated attacker can write and execute code, and the flaw is rated CVSS 8.8 with a very high EPSS score.
Description
NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the UpLoadServlet class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-22724.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated code execution as SYSTEM with CVSS 8.8 and a 98.8th percentile EPSS score, though not in KEV and requiring credentials.
What it is
The UpLoadServlet class in NETGEAR ProSAFE Network Management System fails to validate a user-supplied path before using it in file operations, allowing directory traversal. Because the traversed path feeds file handling, an authenticated attacker can write and execute code, and the flaw is rated CVSS 8.8 with a very high EPSS score.
Impact
An authenticated attacker gains arbitrary code execution in the context of SYSTEM on the affected NETGEAR ProSAFE NMS installation, effectively full control of the host.
Attack surface
Reachable over the network through the UpLoadServlet HTTP endpoint; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates low-privilege authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.46989 (98.8th percentile), indicating elevated predicted exploitation activity; references are only ZDI advisory entries.
What to do
- Apply the NETGEAR vendor fix for the ProSAFE Network Management System as soon as it is available; patch first.
- Restrict network access to the NMS management interface to trusted administrative networks.
- Enforce least privilege and review accounts with upload permissions on the NMS.
- Monitor and, where possible, block traversal sequences in requests to the UpLoadServlet endpoint.
Detection
- Inspect web/proxy logs for requests to UpLoadServlet containing ../ or encoded traversal sequences.
- Alert on unexpected file writes or new executable files in NMS web or application directories.
- Monitor for child processes spawned by the NMS service, especially SYSTEM-level command execution.
- Review NMS accounts and upload activity for anomalous or unauthorized file uploads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-563/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-24-563/ | Third Party AdvisoryVDB Entry |
Track CVE-2024-5505 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5505), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.