Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-46506

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.432
EPSS Ranking 97.4%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2024-46506


Contact Us

Shodan ® - All rights reserved