Impact
An input validation flaw in NETGEAR WAX333 Access Points lets an authenticated user who is already logged on to the local network change device settings that they should not be able to alter. The weakness (CWE‑20) can be exploited only by users with valid credentials, leading to unauthorized configuration changes that affect the integrity and availability of the wireless network service.
Affected Systems
NETGEAR WAX333 Insight Managed WiFi 6 AX3000 Dual‑band Access Point with Gigabit PoE (3‑pack) is affected. Firmware versions prior to V12.8.0.100 contain the flaw; newer firmware includes the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑to‑moderate severity, and an EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. An attacker would need local network access and valid device credentials; the attack vector is an authenticated local access scenario.
OpenCVE Enrichment