cbcvebase.
CVE-2023-33533
published 2023-06-06

CVE-2023-33533: Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

Affected

4 ranges
VendorProductVersion rangeFixed in
netgeard6220_firmware
netgeard8500_firmware
netgearr6700_firmware
netgearr6900_firmware