NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability
CVE-2023-27357
6.5MEDIUM
What is CVE-2023-27357?
NETGEAR RAX30 routers are susceptible to a vulnerability that allows network-adjacent attackers to disclose sensitive information without the need for authentication. The flaw originates from improper handling of SOAP requests, which permits unauthorized access to sensitive functions and data. This vulnerability can be exploited to gain further access, potentially compromising the overall security of the network. For additional information, please refer to the security advisory from NETGEAR and the Zero Day Initiative.
Affected Version(s)
RAX30 1.0.9.90_3