CVE-2023-33533
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-33533 is a new vulnerability affecting several Netgear routers, including the D6220, D8500, R6700, and R6900. These devices have specific firmware versions (1.0.0.80, 1.0.3.60, 1.0.2.26, and 1.0.2.26, respectively) that make them susceptible to Command Injection attacks. Successful exploitation allows attackers to gain web management privileges and subsequently inject commands into post request parameters, ultimately resulting in obtaining shell privileges. This issue poses a significant risk, as unauthorized access to a router's shell can lead to various malicious activities. Users are advised to update their router firmware to the latest versions as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Netgear, Inc.