Input validation error in NETGEAR products - #VU103486
Published: February 3, 2025
Vulnerability identifier: #VU103486
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.
Affected software
XR1000
XR1000v2
XR500
XR1000v2
XR500
Remediation
Install updates from vendor's website.
XR1000 - update to 1.0.0.74
XR1000v2 - update to 1.1.0.22
XR500 - update to 2.3.2.134
XR1000v2 - update to 1.1.0.22
XR500 - update to 2.3.2.134