Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33532


There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.


Published

2023-06-06T14:15:12.740

Last Modified

2025-01-08T16:15:30.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear r6250_firmware 1.0.4.48 Yes
Hardware netgear r6250 - No

References