CVE-2023-33532
Summary
| CVE | CVE-2023-33532 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-06 14:15:00 UTC |
| Updated | 2023-06-12 16:39:00 UTC |
| Description | There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Netgear | R6250 | - | All | All | All |
| Operating System | Netgear | R6250 Firmware | 1.0.4.48 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NETGEAR: Advanced WiFi & Networking | MISC | netgear.com | |
| CVE/Netgear_R6250_RCE.pdf at main · D2y6p/CVE · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.