CVE-2023-33533
 
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-05-22 CVE Reserved
- 2023-06-06 CVE Published
- 2024-06-12 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/D2y6p/CVE/blob/main/Netgear/CVE-2023-33533/Netgear_RCE.pdf | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.netgear.com/about/security | 2023-06-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgear Search vendor "Netgear" | D6220 Firmware Search vendor "Netgear" for product "D6220 Firmware" | 1.0.0.80 Search vendor "Netgear" for product "D6220 Firmware" and version "1.0.0.80" | - |
Affected
| in | Netgear Search vendor "Netgear" | D6220 Search vendor "Netgear" for product "D6220" | - | - |
Safe
|
Netgear Search vendor "Netgear" | D8500 Firmware Search vendor "Netgear" for product "D8500 Firmware" | 1.0.3.60 Search vendor "Netgear" for product "D8500 Firmware" and version "1.0.3.60" | - |
Affected
| in | Netgear Search vendor "Netgear" | D8500 Search vendor "Netgear" for product "D8500" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6700 Firmware Search vendor "Netgear" for product "R6700 Firmware" | 1.0.2.26 Search vendor "Netgear" for product "R6700 Firmware" and version "1.0.2.26" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6700 Search vendor "Netgear" for product "R6700" | - | - |
Safe
|
Netgear Search vendor "Netgear" | R6900 Firmware Search vendor "Netgear" for product "R6900 Firmware" | 1.0.2.26 Search vendor "Netgear" for product "R6900 Firmware" and version "1.0.2.26" | - |
Affected
| in | Netgear Search vendor "Netgear" | R6900 Search vendor "Netgear" for product "R6900" | - | - |
Safe
|