PT-2024-2649 · NetGear · Netgear Dgnd4000

Published

2024-03-14

·

Updated

2024-08-14

·

CVE-2023-50677

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NETGEAR-DGND4000 version 1.1.00.15 1.00.15
Description The issue allows a remote attacker to escalate privileges via the next file parameter to the "/setup.cgi" component. This is related to inadequate access control in the NETGEAR DGND4000 router's embedded software.
Recommendations For version 1.1.00.15 1.00.15, consider disabling access to the "/setup.cgi" component until a patch is available. Avoid using the next file parameter in the affected component to minimize the risk of exploitation.

Fix

Improper Privilege Management

Improper Verification of Cryptographic Signature

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-02716
CVE-2023-50677

Affected Products

Netgear Dgnd4000