PT-2023-2335 · NetGear · Netgear Nighthawk Wifi6 Router
Published
2023-03-15
·
Updated
2023-03-21
·
CVE-2023-28337
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netgear Nighthawk Wifi6 Router (RAX30) (affected versions not specified)
Description
The issue is related to a lack of access control in the firmware image upload handler of the Netgear Nighthawk Wifi6 Router (RAX30). A hidden
forceFWUpdate parameter can be used to force the upgrade to complete, bypassing certain validation checks. This allows end users to upload modified, unofficial, and potentially malicious firmware to the device. The vulnerability can be exploited by a remote attacker to execute arbitrary code.Recommendations
As a temporary workaround, consider disabling the firmware upload feature until a patch is available.
Restrict access to the firmware upload module to minimize the risk of exploitation.
Avoid using the
forceFWUpdate parameter in the firmware upload process until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear Nighthawk Wifi6 Router