CVE-2024-20335

MEDIUM
Published Mar 6, 2024 Modified Aug 5, 2025 CWE-78

Description

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform command injection attacks against an affected device. In order to exploit this vulnerability, the attacker must have valid administrative credentials for the device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system.

Is your site exposed to CVE-2024-20335?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Weakness Type (CWE)

CWE-78 OS Command Injection

Affected Products

Vendor Product
cisco wap121_firmware
cisco wap121
cisco wap125_firmware
cisco wap125
cisco wap131_firmware
cisco wap131
cisco wap150_firmware
cisco wap150
cisco wap320_firmware
cisco wap320
cisco wap321_firmware
cisco wap321
cisco wap351_firmware
cisco wap351
cisco wap361_firmware
cisco wap361
cisco wap571_firmware
cisco wap571
cisco wap371_firmware
cisco wap371
cisco wap571e_firmware
cisco wap571e
cisco wap581_firmware
cisco wap581

References

Frequently Asked Questions

What is CVE-2024-20335? +
A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform command injection attacks against an affected device. In order to exploit this vulnerability, the attacker must have valid administrative credentials for the device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. It has a CVSS v3.1 base score of 6.5 (MEDIUM).
How severe is CVE-2024-20335? +
CVE-2024-20335 has a CVSS v3.1 score of 6.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-20335? +
CVE-2024-20335 affects products from cisco, specifically: wap121, wap121_firmware, wap125, wap125_firmware, wap131, wap131_firmware, wap150, wap150_firmware, wap320, wap320_firmware, wap321, wap321_firmware, wap351, wap351_firmware, wap361, wap361_firmware, wap371, wap371_firmware, wap571, wap571_firmware, wap571e, wap571e_firmware, wap581, wap581_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-20335? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-20335 — free, no signup required.