CVE-2023-48725
published 2024-03-07CVE-2023-48725: A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially…
PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
19.51%
97.1th percentile
A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rax30 | — | — |
| netgear | rax30 | — | — |
| netgear | rax30_firmware | — | — |
| netgear | rax30_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation involves a specially crafted HTTP request targeting the JSON Parsing getblockschedule() functionality of the Netgear RAX30, triggering a stack-based buffer overflow leading to code execution. ↗
- ·Affected versions are Netgear RAX30 firmware 1.0.11.96 and 1.0.7.78; detection/patching efforts should confirm firmware version on monitored devices. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Netgear wireless router open to code execution after buffer overflow vulnerability
blogs_talos·2024-03-20·CVSS 7.2
[HIGH] Netgear wireless router open to code execution after buffer overflow vulnerability
## Netgear wireless router open to code execution after buffer overflow vulnerability
Cisco Talos’ Vulnerability Research team recently disclosed three vulnerabilities across a range of products, including one that could lead to remote code execution in a popular Netgear wireless router designed for home networks.
There is also a newly disclosed vulnerability in a graphics driver for some NVIDIA GPUs that could lead to a memory leak.
All the vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org , and our latest Vulnerability Advisories are always posted on
Talos
Netgear wireless router open to code execution after buffer overflow vulnerability
blogs_talos·2024-03-20·CVSS 7.2
[HIGH] Netgear wireless router open to code execution after buffer overflow vulnerability
Cisco Talos’ Vulnerability Research team recently disclosed three vulnerabilities across a range of products, including one that could lead to remote code execution in a popular Netgear wireless router designed for home networks.
There is also a newly disclosed vulnerability in a graphics driver for some NVIDIA GPUs that could lead to a memory leak.
All the vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
## Netgear RAX30 JSON parsing stack-based buffer overflow
https://kb.netgear.com/000066037/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-the-RAX30-PSV-2023-0160https://talosintelligence.com/vulnerability_reports/TALOS-2023-1887https://kb.netgear.com/000066037/Security-Advisory-for-Post-Authentication-Stack-Overflow-on-the-RAX30-PSV-2023-0160https://talosintelligence.com/vulnerability_reports/TALOS-2023-1887https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1887
2024-03-07
Published