ZeroHour

CVE-2023-33533

PoC
CVSS 3.1
8.8 high
EPSS
3%p87
Published
()
Modified
Description

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

Vendors
netgear
Products
d6220 firmware, d8500 firmware, r6700 firmware, r6900 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.