PT-2023-2726 · NetGear · Netgear Rax30
Noam Moshe
+3
·
Published
2023-01-24
·
Updated
2025-01-03
·
CVE-2023-27357
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NETGEAR RAX30 (affected versions not specified)
Description
This issue allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. The specific flaw exists within the handling of SOAP requests, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this to disclose sensitive information, leading to further compromise.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netgear Rax30