CVE-2023-30280
Description
Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in Netgear R6900, R6700v3, and R6700 firmware allows remote attackers to execute arbitrary code or cause denial of service via the getInputData parameter in fwSchedule.cgi.
Vulnerability
A buffer overflow vulnerability exists in the getInputData parameter of the fwSchedule.cgi page on Netgear R6900 firmware v1.0.2.26, R6700v3 firmware v1.0.4.128, and R6700 firmware v1.0.0.26 [1]. The vulnerability allows a remote attacker to cause a buffer overflow by sending a crafted request to this CGI endpoint without requiring authentication.
Exploitation
An attacker does not need any prior authentication to exploit this vulnerability. The attack is conducted remotely by sending a specially crafted HTTP request to the vulnerable router's fwSchedule.cgi endpoint with an overly long getInputData parameter. The improper bounds checking on this input leads to a buffer overflow condition on the stack.
Impact
Successful exploitation of this buffer overflow allows a remote attacker to execute arbitrary code on the router in the context of the web server or cause a denial of service (DoS) [1]. This can lead to complete compromise of the device, including potential further attacks on the local network.
Mitigation
As of the publication date (2023-04-26), Netgear has not yet released a firmware update to address this vulnerability [1]. Users of affected Netgear models should monitor Netgear's security advisory page for future patches. No known workarounds are reported. The affected products may be past their end-of-life support; users should consider upgrading to a supported model.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.