PT-2023-7869 · NetGear · Netgear Wnr2000V4

Published

2023-11-30

·

Updated

2023-12-19

·

CVE-2023-50089

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR WNR2000v4 version 1.0.0.70
Description A Command Injection issue exists when using HTTP for SOAP authentication, allowing command execution after successful authentication. This can be exploited by sending specially crafted HTTP requests, potentially enabling remote attackers to execute arbitrary commands. The vulnerability is related to the soap auth() function and inadequate data sanitization on the management level.
Recommendations For NETGEAR WNR2000v4 version 1.0.0.70, consider disabling the soap auth() function until a patch is available to prevent command injection attacks. Restrict access to the SOAP authentication process to minimize the risk of exploitation. Avoid using HTTP for SOAP authentication until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-08940
CVE-2023-50089

Affected Products

Netgear Wnr2000V4