VYPR
Unrated severityNVD Advisory· Published Apr 26, 2023· Updated Feb 3, 2025

CVE-2023-30280

CVE-2023-30280

Description

Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in Netgear R6900, R6700v3, and R6700 firmware allows remote attackers to execute arbitrary code or cause denial of service via the getInputData parameter in fwSchedule.cgi.

Vulnerability

A buffer overflow vulnerability exists in the getInputData parameter of the fwSchedule.cgi page on Netgear R6900 firmware v1.0.2.26, R6700v3 firmware v1.0.4.128, and R6700 firmware v1.0.0.26 [1]. The vulnerability allows a remote attacker to cause a buffer overflow by sending a crafted request to this CGI endpoint without requiring authentication.

Exploitation

An attacker does not need any prior authentication to exploit this vulnerability. The attack is conducted remotely by sending a specially crafted HTTP request to the vulnerable router's fwSchedule.cgi endpoint with an overly long getInputData parameter. The improper bounds checking on this input leads to a buffer overflow condition on the stack.

Impact

Successful exploitation of this buffer overflow allows a remote attacker to execute arbitrary code on the router in the context of the web server or cause a denial of service (DoS) [1]. This can lead to complete compromise of the device, including potential further attacks on the local network.

Mitigation

As of the publication date (2023-04-26), Netgear has not yet released a firmware update to address this vulnerability [1]. Users of affected Netgear models should monitor Netgear's security advisory page for future patches. No known workarounds are reported. The affected products may be past their end-of-life support; users should consider upgrading to a supported model.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.