Command Injection Vulnerabilities in Netgear WG302v2 and WAG302v2
CVE-2023-38921

8.8HIGH

Key Information:

Vendor

Netgear

Vendor
CVE Published:
7 August 2023

What is CVE-2023-38921?

The WG302v2 and WAG302v2 from Netgear have been found to have multiple command injection vulnerabilities in their firmware upgrade_handler function. These vulnerabilities are exploited through the firmwareRestore and firmwareServerip parameters, which could potentially allow an attacker to execute arbitrary commands on the affected devices. Users are advised to apply the necessary security updates to mitigate the risks associated with these vulnerabilities.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.