Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters.
References
Link | Resource |
---|---|
https://github.com/FirmRec/IoT-Vulns/tree/main/netgear/upgrade_handler | Third Party Advisory |
https://www.netgear.com/about/security/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-08-07T00:00:00
Updated: 2023-08-07T00:00:00
Reserved: 2023-07-25T00:00:00
Link: CVE-2023-38921
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-08-07T19:15:10.393
Modified: 2023-08-09T18:03:20.593
Link: CVE-2023-38921
JSON object: View
Redhat Information
No data.
CWE