Aller au contenu

Fiche vulnérabilité

CVE-2023-28337 : faille élevée netgear rax30 firmware (CVSS 8.8)

Description

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
15 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • netgear rax30 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE