PT-2022-6574 · NetGear · Netgear Rax30

Rocco Calvi

+1

·

Published

2022-11-30

·

Updated

2025-01-03

·

CVE-2023-27360

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR RAX30 (affected versions not specified)
Description This issue allows network-adjacent attackers to execute arbitrary code on affected installations. The flaw exists within the configuration of the lighttpd HTTP server, resulting from allowing execution of files from untrusted sources. An attacker can leverage this to execute code in the context of root. Authentication is not required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Origin Validation Error

Weakness Enumeration

Related Identifiers

BDU:2023-02574
CVE-2023-27360
ZDI-23-496

Affected Products

Netgear Rax30