CVE-2023-33532: Command Injection
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netgear R6250 routerto a version that resolves this vulnerability.Fixed in 1.0.4.48
Event History
Frequently Asked Questions
What is CVE-2023-33532?
CVE-2023-33532 is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48.
How severe is CVE-2023-33532?
CVE-2023-33532 has a severity rating of 9.8 (critical).
How does CVE-2023-33532 affect the Netgear R6250 router?
CVE-2023-33532 allows an attacker with web management privileges to inject commands into post request parameters, thereby gaining shell privileges on the router.
Which version of the Netgear R6250 firmware is affected by CVE-2023-33532?
CVE-2023-33532 affects Netgear R6250 firmware version 1.0.4.48.
Is the Netgear R6250 router itself vulnerable to CVE-2023-33532?
No, the Netgear R6250 router itself is not vulnerable to CVE-2023-33532.