CVE-2023-33533

CWE-77Command Injection3 documents3 sources
Severity
8.8HIGH
EPSS
6.5%
top 8.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6

Description

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-6hv6-62gq-jmq6: Netgear D6220 with Firmware Version 12023-06-06
CVEList
CVE-2023-33533: Netgear D6220 with Firmware Version 12023-06-06
CVE-2023-33533 (HIGH CVSS 8.8) | Netgear D6220 with Firmware Version | cvebase.io