First published: Tue Feb 04 2025(Updated: )
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.
Credit: disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netgear FVS336Gv2 | ||
NETGEAR FVS336Gv3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23690 is categorized as a critical severity vulnerability due to its potential for remote command execution.
The recommended fix for CVE-2024-23690 is to discontinue use of the Netgear FVS336Gv2 and FVS336Gv3 devices since they are end-of-life.
CVE-2024-23690 affects users of the end-of-life Netgear FVS336Gv2 and FVS336Gv3 routers.
Yes, CVE-2024-23690 can be exploited remotely by an authenticated attacker via the Telnet interface.
CVE-2024-23690 is a command injection vulnerability in the Telnet interface of the affected devices.