CVE-2023-50089

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.70:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr2000:v4:*:*:*:*:*:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
References () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - Exploit, Third Party Advisory () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - Exploit, Third Party Advisory
References () https://www.netgear.com/about/security/ - Vendor Advisory () https://www.netgear.com/about/security/ - Vendor Advisory

19 Dec 2023, 20:51

Type Values Removed Values Added
First Time Netgear wnr2000 Firmware
Netgear
Netgear wnr2000
CPE cpe:2.3:h:netgear:wnr2000:v4:*:*:*:*:*:*:*
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.70:*:*:*:*:*:*:*
References () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - Exploit, Third Party Advisory
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en NETGEAR WNR2000v4 versión 1.0.0.70. Cuando se utiliza HTTP para la autenticación SOAP, la ejecución del comando se produce durante el proceso después de una autenticación exitosa.

15 Dec 2023, 20:09

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 17:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-50089

Mitre link : CVE-2023-50089

CVE.ORG link : CVE-2023-50089


JSON object : View

Products Affected

netgear

  • wnr2000
  • wnr2000_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')