When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published: 2023-03-15T00:00:00

Updated: 2024-08-02T12:38:24.987Z

Reserved: 2023-03-14T00:00:00

Link: CVE-2023-28337

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-03-15T23:15:09.897

Modified: 2023-03-21T17:40:15.477

Link: CVE-2023-28337

cve-icon Redhat

No data.