CVE-2024-35520: NETGEAR r7000 Firmware

Medium severity, CVSS 6.8. EPSS: 9.6% chance of exploitation in the next 30 days.

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Affected products

  • NETGEAR r7000 Firmware: version 1.0.11.136 only

Published 2024-10-14. Last modified 2026-06-17.