CVE-2023-38928: Command Injection
Published Aug 7, 2023
·Updated
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usbremoteinvite.cgi.
Affected Software
2 affected components
Netgear R7100lg Firmware=1.0.0.78
Netgear R7100LG
Event History
Aug 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38928?
CVE-2023-38928 is a command injection vulnerability found in Netgear R7100LG firmware version 1.0.0.78.
2
How severe is CVE-2023-38928?
CVE-2023-38928 has a severity rating of 9.8 (critical).
3
What software is affected by CVE-2023-38928?
Netgear R7100LG firmware version 1.0.0.78 is affected by CVE-2023-38928.
4
How can CVE-2023-38928 be exploited?
CVE-2023-38928 can be exploited by injecting malicious commands through the 'password' parameter in the usb_remote_invite.cgi script.
5
Are there any known references for CVE-2023-38928?
Yes, you can find more information about CVE-2023-38928 on the GitHub page for IoT-Vulns and the Netgear security advisory.