HIGH✓ PATCH🇬🇧 English

CVE-2023-41183

CVSS 8.8v3.0pub. 2024-05-03upd. 2025-08-08

NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR Orbi 760 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SOAP API. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-20524.

oryginał EN
CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netgear Rbr760

    HW
    Netgear
    wszystkie wersje
  • Netgear Rbr760 Firmware

    OS
    Netgear
    < 6.3.8.5
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Auth Bypass
CWE
Referencje

Powiązane podatności

CVE-2026-0411MEDIUM4.2ten sam produkt

Luka ujawniania informacji w satelitach NETGEAR Orbi (seria RBR/RBE/RBS) mogłaby umożliwić użytkownikowi połąc...

CVE-2020-26919CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Brak kontroli dostępu na poziomie funkcji w NETGEAR JGS516PE

CVE-2017-6862CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Buffer overflow w routerach NETGEAR WNR2000 umożliwia RCE bez uwierzytelnienia

CVE-2016-1555CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Command injection w firmwarze Netgear — zdalne wykonanie kodu

CVE-2017-6077CRITICAL9.8⚠ KEVPL ✓ten sam vendor

Command injection w NETGEAR DGN2200 przez ping.cgi