The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://vulncheck.com/advisories/netgear-fvs336g-rce |
|
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 04 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands. | |
| Title | EOL Netgear FVS336v3 Telnet Configuration Backup Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-02-04T14:34:00.370Z
Updated: 2025-02-04T14:58:15.609Z
Reserved: 2024-01-19T17:35:14.201Z
Link: CVE-2024-23690
Updated: 2025-02-04T14:55:41.892Z
Status : Received
Published: 2025-02-04T15:15:17.973
Modified: 2025-02-04T15:15:17.973
Link: CVE-2024-23690
No data.