← All CVEs

CVE-2023-38925

high · 8.8

Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi.

8.8
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2023-08-07
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
netgeardc112a_firmware1.0.0.64
netgeardc112aall versions
netgearex6200_firmware1.0.3.94
netgearex6200all versions
netgearr6300v2_firmware1.0.4.8
netgearr6300v2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-38925