VulnerabilityModified
CVE-2023-33532
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48.
CRITICAL 9.8EPSS 16.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 16.17% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- netgear/r6250 firmware
- Source
- cve@mitre.org
References
- https://github.com/D2y6p/CVE/blob/main/Netgear/CVE-2023-33532/Netgear_R6250_RCE.pdfExploit, Third Party Advisory
- https://github.com/D2y6p/CVE/blob/main/Netgear/CVE-2023-33532/Netgear_R6250_RCE.pdfExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.