← Back

CVE-2023-28337

nvd nist
Published: Mar 15, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.

Affected (1)

1 product
Rax30 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netgear
Rax30
All versions

References (2)

Source: vulnreport@tenable.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.