Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33533


Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.


Published

2023-06-06T14:15:12.817

Last Modified

2025-01-08T16:15:30.463

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear d6220_firmware 1.0.0.80 Yes
Hardware netgear d6220 - No
Operating System netgear d8500_firmware 1.0.3.60 Yes
Hardware netgear d8500 - No
Operating System netgear r6700_firmware 1.0.2.26 Yes
Hardware netgear r6700 - No
Operating System netgear r6900_firmware 1.0.2.26 Yes
Hardware netgear r6900 - No

References