An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via crafted input.
CVE ID: CVE-2024-53942
Vendor: n/a
Product: n/a
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 18.32% (scored less or equal to compared to others)
EPSS Date: 2025-03-04 (when was this score calculated)