NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.
2020-03-23T15:15:14.597
2024-11-21T02:45:19.230
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | prosafe_wc9500_firmware | 5.1.0.17 | Yes |
Hardware | netgear | prosafe_wc9500 | - | No |
Operating System | netgear | prosafe_wc7600_firmware | 5.1.0.17 | Yes |
Hardware | netgear | prosafe_wc7600 | - | No |
Operating System | netgear | prosafe_wc7520_firmware | 2.5.0.35 | Yes |
Hardware | netgear | prosafe_wc7520 | - | No |