CVE-2023-27852
- EPSS 0.81%
- Veröffentlicht 10.03.2023 18:15:17
- Zuletzt bearbeitet 27.02.2025 21:15:20
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
CVE-2023-27851
- EPSS 0.77%
- Veröffentlicht 10.03.2023 18:15:17
- Zuletzt bearbeitet 27.02.2025 22:15:36
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that unintentionally allows users with upload permissions to execute arbitrary code on the device.
CVE-2023-27850
- EPSS 0.34%
- Veröffentlicht 10.03.2023 18:15:16
- Zuletzt bearbeitet 28.02.2025 17:15:15
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device.
CVE-2023-1205
- EPSS 0.27%
- Veröffentlicht 10.03.2023 18:15:16
- Zuletzt bearbeitet 28.02.2025 17:15:13
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections.
CVE-2022-47210
- EPSS 0.4%
- Veröffentlicht 16.12.2022 20:15:09
- Zuletzt bearbeitet 17.04.2025 19:15:54
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated u...
CVE-2022-47209
- EPSS 0.48%
- Veröffentlicht 16.12.2022 20:15:08
- Zuletzt bearbeitet 17.04.2025 19:15:54
A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and cannot be changed by a user via any normally accessible means.