Vulnerability Details CVE-2023-28338
Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the request body being written to “/tmp/mulipartFile” on the device itself. A sufficiently large file will cause device resources to be exhausted, resulting in the device becoming unusable until it is rebooted.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-28338
-
cpe:2.3:h:netgear:rax30:-
-
cpe:2.3:o:netgear:rax30_firmware:-
-
cpe:2.3:o:netgear:rax30_firmware:1.0.10.94
-
cpe:2.3:o:netgear:rax30_firmware:1.0.11.96
-
cpe:2.3:o:netgear:rax30_firmware:1.0.11.96_2_hotfix
-
cpe:2.3:o:netgear:rax30_firmware:1.0.12.100_hotfix
-
cpe:2.3:o:netgear:rax30_firmware:1.0.3.64
-
cpe:2.3:o:netgear:rax30_firmware:1.0.4.66
-
cpe:2.3:o:netgear:rax30_firmware:1.0.5.70
-
cpe:2.3:o:netgear:rax30_firmware:1.0.6.74
-
cpe:2.3:o:netgear:rax30_firmware:1.0.7.78
-
cpe:2.3:o:netgear:rax30_firmware:1.0.9.90
-
cpe:2.3:o:netgear:rax30_firmware:1.0.9.92