NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability
CVE-2023-34283
4.6MEDIUM
What is CVE-2023-34283?
A significant information disclosure vulnerability has been identified in NETGEAR RAX30 routers, stemming from the improper handling of symbolic links on removable USB devices. This flaw enables a physically present attacker to create symbolic links that manipulate the router's web server into revealing arbitrary local files. The absence of authentication requirements magnifies the risk, as any individual with physical access can potentially leverage this vulnerability to access sensitive information in the context of root. For more information, refer to the advisories from the Zero Day Initiative and NETGEAR's security resources.
Affected Version(s)
RAX30 1.0.9.92_1