Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28338


Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device resources to be exhausted, resulting in the device becoming unusable until it is rebooted.


Published

2023-03-15T23:15:09.957

Last Modified

2024-11-21T07:54:52.673

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear rax30_firmware * Yes
Hardware netgear rax30 - No

References