CVE-2023-50677

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netgear:dgnd4000_firmware:1.1.00.15:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dgnd4000:-:*:*:*:*:*:*:*

History

28 Jul 2025, 17:04

Type Values Removed Values Added
References () https://gist.github.com/DMIND-NLL/b61b8d8d20271adf60fc717b3b48faff - () https://gist.github.com/DMIND-NLL/b61b8d8d20271adf60fc717b3b48faff - Broken Link
First Time Netgear dgnd4000 Firmware
Netgear dgnd4000
Netgear
CPE cpe:2.3:o:netgear:dgnd4000_firmware:1.1.00.15:*:*:*:*:*:*:*
cpe:2.3:h:netgear:dgnd4000:-:*:*:*:*:*:*:*

21 Nov 2024, 08:37

Type Values Removed Values Added
References () https://gist.github.com/DMIND-NLL/b61b8d8d20271adf60fc717b3b48faff - () https://gist.github.com/DMIND-NLL/b61b8d8d20271adf60fc717b3b48faff -

14 Aug 2024, 19:35

Type Values Removed Values Added
Summary
  • (es) Un problema en NETGEAR-DGND4000 v.1.1.00.15_1.00.15 permite a un atacante remoto escalar privilegios a través del parámetro next_file al componente /setup.cgi.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-269

14 Mar 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-14 22:15

Updated : 2025-07-28 17:04


NVD link : CVE-2023-50677

Mitre link : CVE-2023-50677

CVE.ORG link : CVE-2023-50677


JSON object : View

Products Affected

netgear

  • dgnd4000_firmware
  • dgnd4000
CWE
CWE-269

Improper Privilege Management