CVE-2023-47463: Critical severity netgear nighthawk ax1800 firmware vulnerability
Published Nov 30, 2023
·Updated
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the glnassys authentication function.
Affected Software
2 affected components
All of the following
gl-inet Gl-ax1800 Firmware>=4.0.0<4.5.0
gl-inet GL-AX1800
Event History
Nov 30, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-47463.
2
What is the severity of CVE-2023-47463?
The severity of CVE-2023-47463 is critical with a CVSS score of 9.8.
3
What is the affected software version range?
The affected software version range is from 4.0.0 to 4.5.0.
4
How can a remote attacker exploit CVE-2023-47463?
A remote attacker can exploit CVE-2023-47463 by executing arbitrary code through a crafted script to the gl_nas_sys authentication function.
5
Is there a reference for more details about CVE-2023-47463?
Yes, you can refer to the following link for more details: [GitHub - GL.iNet CVE-issues](https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/an%20unauthenticated%20remote%20code%20execution.md).