VYPR

Xavn2001v2 Firmware

by Netgear

CVEs (3)

  • CVE-2023-39550HigAug 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the check_auth function.

  • CVE-2023-38922HigAug 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function.

  • CVE-2023-23110HigFeb 2, 2023
    risk 0.48cvss 7.4epss 0.01

    An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image…