Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 1.0.0.74
affected
Default status
unaffected
Any version before 1.1.0.22
affected
Default status
unaffected
Any version before 2.3.2.134
affected
Description
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 1.0.0.74
Any version before 1.1.0.22
Any version before 2.3.2.134
References
kb.netgear.com/...ted-RCE-on-Some-WiFi-Routers-PSV-2023-0039