NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability
CVE-2023-35721
Summary
An improper certificate validation vulnerability affects several versions of NETGEAR routers, allowing potential exploitation by network-adjacent attackers. This vulnerability arises from inadequate validation of the certificate presented by the update server. In successful exploits, this misconfiguration could allow attackers to execute arbitrary code with root privileges, effectively compromising the integrity of any downloaded information. As this flaw does not require authentication, it represents a significant risk for users who have not applied necessary firmware updates and security measures. Organizations utilizing affected NETGEAR routers should prioritize patching and monitoring security advisories to mitigate potential threats.
Affected Version(s)
Multiple Routers 1.0.12.120_2.0.83
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved