VYPR

Nighthawk WiFi6 Router

by Netgear

CVEs (7)

  • CVE-2023-27853CriMar 10, 2023
    risk 0.65cvss 9.8epss 0.20

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

  • CVE-2023-27852CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.

  • CVE-2023-28337HigMar 15, 2023
    risk 0.57cvss 8.8epss 0.01

    When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially…

  • CVE-2023-27851HigMar 10, 2023
    risk 0.57cvss 8.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.

  • CVE-2023-1205HigMar 10, 2023
    risk 0.57cvss 8.8epss 0.00

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.

  • CVE-2023-28338HigMar 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device…

  • CVE-2023-27850MedMar 10, 2023
    risk 0.44cvss 6.8epss 0.00

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.