← All CVEs

CVE-2023-33532

critical · 9.8

There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.

9.8
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2023-06-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
netgearr6250_firmware1.0.4.48
netgearr6250all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-33532