Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
2024-11-05T15:15:23.960
2025-04-22T18:13:30.633
Analyzed
CVSSv3.1: 5.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netgear | r8500_firmware | 1.0.2.160 | Yes |
Hardware | netgear | r8500 | - | No |