ZeroHour

CVE-2023-33532

PoC
CVSS 3.1
9.8 critical
EPSS
16%p97
Published
()
Modified
Description

There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.

Vendors
netgear
Products
r6250 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.