Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48725


A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.


Published

2024-03-07T15:15:07.733

Last Modified

2025-03-11T16:56:47.143

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-121
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System netgear rax30_firmware 1.0.7.78 Yes
Operating System netgear rax30_firmware 1.0.11.96 Yes
Hardware netgear rax30 - No

References