PT-2023-2117 · NetGear · Netgear Nighthawk Wifi6 Router
Evan Grant
+1
·
Published
2023-03-06
·
Updated
2025-02-28
·
CVE-2023-27850
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NETGEAR Nighthawk WiFi6 Router versions prior to V1.0.10.94
Description
The issue is related to the file sharing mechanism in the NETGEAR Nighthawk WiFi6 Router, which allows users with access to this feature to access arbitrary files on the device. This is due to insufficient access control in the file sharing component of the router's software. Exploitation of this issue may allow a remote attacker to gain access to arbitrary files.
Recommendations
For versions prior to V1.0.10.94, update to version V1.0.10.94 or later to resolve the issue. As a temporary workaround, consider restricting access to the file sharing feature until a patch is applied.
Fix
Improper Access Control
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear Nighthawk Wifi6 Router