Command Injection Vulnerability in Netgear R7100LG Router
CVE-2023-38928

9.8CRITICAL

Key Information:

Vendor
Netgear
Vendor
CVE Published:
7 August 2023

Summary

The Netgear R7100LG router is susceptible to a command injection vulnerability that can be exploited through the password parameter in the usb_remote_invite.cgi script. This flaw may allow attackers to execute arbitrary commands on the device, potentially compromising the router's integrity and security. Users of this device should take precautionary measures to protect their network and check for available firmware updates.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.