CVE-2023-38925: Buffer Overflow
Published Aug 7, 2023
·Updated
Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the httppasswd parameter in password.cgi.
Affected Software
6 affected components
Netgear Dc112a Firmware=1.0.0.64
Netgear DC112A
Netgear Ex6200 Firmware=1.0.3.94
Netgear EX6200
Netgear R6300v2 Firmware=1.0.4.8
Netgear R6300v2
Event History
Aug 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Netgear vulnerability?
The vulnerability ID for this Netgear vulnerability is CVE-2023-38925.
2
What is the severity level of CVE-2023-38925?
CVE-2023-38925 has a severity level of high.
3
Which Netgear devices are affected by CVE-2023-38925?
Netgear DC112A 1.0.0.64, EX6200 1.0.3.94, and R6300v2 1.0.4.8 are affected by CVE-2023-38925.
4
What is the cause of the vulnerability?
The vulnerability is caused by a buffer overflow in the http_passwd parameter in password.cgi.
5
Are there any fixes or patches available for CVE-2023-38925?
Netgear has released firmware updates to address the CVE-2023-38925 vulnerability. It is recommended to update to the latest firmware version provided by Netgear for the affected devices.