References https://nvd.nist.gov/vuln/detail/CVE-2023-38095 https://www.zerodayinitiative.com/advisories/ZDI-23-921/ https://github.com/advisories/GHSA-v2fh-w9pr-6754 https://kb.netgear.com/000065707/Security-Advisory-for-Multiple-Vulnerabilities-on-the-ProSAFE-Network-Management-System-PSV-2023-0024-PSV-2023-0025 https://www.cnvd.org.cn/flaw/show/CNVD-2024-33897 https://www.nsfocus.net/vulndb/98635 https://dbugs.ptsecurity.com/vulnerability/PT-2023-3789 https://www.tenable.com/plugins/nessus/181469 https://update.nsfocusglobal.com/update/listNewipsDetail/v/rule5.6.11 https://advisories.checkpoint.com/defense/advisories/public/2025/cpai-2023-2323.html https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:CTS:NETGEAR-NMS300-FUPLD.html https://www.snort.org/rule_docs/1-66488 https://docs.sophos.com/releasenotes/output/en-us/nsg/IPSReleaseNotes/7.21.16_s.pdf https://1275.ru/cve/cve-2023-38095-chtenie-lokalnyh-faylov-v-netgear-nms300_4892 https://support.trellix.com/s/article/000013921
Related VulnerabilitiesNetgear DGN2200 路由器 /RST_status.htm 权限绕过漏洞(CVE-2024-57046)PoCCVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command InjectionPoCCVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password DisclosurePoCCVE-2016-6277: NETGEAR Routers - Remote Code ExecutionPoCCVE-2017-5521: NETGEAR Routers - Authentication BypassPoCCVE-2020-26919: NETGEAR ProSAFE Plus - Unauthenticated Remote Code ExecutionPoCCVE-2020-27866: NETGEAR - Authentication BypassPoCCVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunPoCCVE-2022-29383: NETGEAR ProSafe SSL VPN firmware - SQL InjectionPoCCVE-2024-30568: Netgear R6850 V1.1.0.88 - Command InjectionPoCCVE-2024-30569: Netgear R6850 - Information DisclosurePoCCVE-2024-30570: Netgear R6850 - Information DisclosurePoCCVE-2024-57046: Netgear DGN2200 - Improper Authentication