First published: Mon Aug 07 2023(Updated: )
Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear Jwnr2000v2 Firmware | =1.0.0.11 | |
Netgear JWNR2000v2 | ||
Netgear Xwn5001 Firmware | =0.4.1.1 | |
Netgear XWN5001 | ||
Netgear Xavn2001v2 Firmware | =0.4.0.7 | |
Netgear Xavn2001v2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39550 is a vulnerability found in Netgear JWNR2000v2, XWN5001, and XAVN2001v2 devices that allows for multiple buffer overflows via the http_passwd and http_username parameters.
The severity of CVE-2023-39550 is high with a severity value of 8.8.
CVE-2023-39550 can be exploited by sending malicious input to the http_passwd and http_username parameters in the check_auth function.
Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 are affected by CVE-2023-39550.
To fix CVE-2023-39550, it is recommended to update the firmware of the affected Netgear devices to the latest version.