cbcvebase.
CVE-2023-48725
published 2024-03-07

CVE-2023-48725: A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially…

PriorityP268high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
19.51%
97.1th percentile
A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Affected

4 ranges
VendorProductVersion rangeFixed in
netgearrax30
netgearrax30
netgearrax30_firmware
netgearrax30_firmware

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation involves a specially crafted HTTP request targeting the JSON Parsing getblockschedule() functionality of the Netgear RAX30, triggering a stack-based buffer overflow leading to code execution.
  • ·Affected versions are Netgear RAX30 firmware 1.0.11.96 and 1.0.7.78; detection/patching efforts should confirm firmware version on monitored devices.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.