CVE-2023-50089

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.70:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr2000:v4:*:*:*:*:*:*:*

History

19 Dec 2023, 20:51

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en NETGEAR WNR2000v4 versión 1.0.0.70. Cuando se utiliza HTTP para la autenticación SOAP, la ejecución del comando se produce durante el proceso después de una autenticación exitosa.
References () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - () https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md - Exploit, Third Party Advisory
References () https://www.netgear.com/about/security/ - () https://www.netgear.com/about/security/ - Vendor Advisory
CWE CWE-77
First Time Netgear
Netgear wnr2000 Firmware
Netgear wnr2000
CPE cpe:2.3:o:netgear:wnr2000_firmware:1.0.0.70:*:*:*:*:*:*:*
cpe:2.3:h:netgear:wnr2000:v4:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

15 Dec 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-15 17:15

Updated : 2023-12-19 20:51


NVD link : CVE-2023-50089

Mitre link : CVE-2023-50089

CVE.ORG link : CVE-2023-50089


JSON object : View

Products Affected

netgear

  • wnr2000
  • wnr2000_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')