CVE Database
/

CVE-2023-28337

Back to search

CVE-2023-28337

Published: Mar 15, 2023

Modified: Feb 27, 2025

PUBLISHED

Description

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.

VendorProductVersions

n/a

NETGEAR Nighthawk WiFi6 Router (RAX30)

affected
All known versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now