CVE-2024-26519: Casa Systems Ntc-221 Firmware

Critical severity, CVSS 9.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi component.

Affected products

Published 2024-10-22. Last modified 2026-06-17.