NETGEAR Multiple Routers curl_post Improper Certificate Validation Remote Code Execution Vulnerability
CVE-2023-35721

8.1HIGH

Key Information:

Vendor
Netgear
Vendor
CVE Published:
3 May 2024

Summary

An improper certificate validation vulnerability affects several versions of NETGEAR routers, allowing potential exploitation by network-adjacent attackers. This vulnerability arises from inadequate validation of the certificate presented by the update server. In successful exploits, this misconfiguration could allow attackers to execute arbitrary code with root privileges, effectively compromising the integrity of any downloaded information. As this flaw does not require authentication, it represents a significant risk for users who have not applied necessary firmware updates and security measures. Organizations utilizing affected NETGEAR routers should prioritize patching and monitoring security advisories to mitigate potential threats.

Affected Version(s)

Multiple Routers 1.0.12.120_2.0.83

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.