References https://nvd.nist.gov/vuln/detail/CVE-2023-50089 https://github.com/advisories/GHSA-46jg-h552-883r https://access.redhat.com/security/cve/cve-2023-50089 https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2023-50089 https://www.netgear.com/about/security/ https://kb.netgear.com/000036549/Insecure-Remote-Access-and-Command-Execution-Security-Vulnerability https://vulmon.com/searchpage?q=netgear+wnr2000+firmware https://github.com/NoneShell/Vulnerabilities/blob/main/NETGEAR/WNR2000v4-1.0.0.70-Authorized-Command-Injection.md
Related VulnerabilitiesNetgear DGN2200 路由器 /RST_status.htm 权限绕过漏洞(CVE-2024-57046)PoCCVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command InjectionPoCCVE-2016-5649: NETGEAR DGN2200 / DGND3700 - Admin Password DisclosurePoCCVE-2016-6277: NETGEAR Routers - Remote Code ExecutionPoCCVE-2017-5521: NETGEAR Routers - Authentication BypassPoCCVE-2020-26919: NETGEAR ProSAFE Plus - Unauthenticated Remote Code ExecutionPoCCVE-2020-27866: NETGEAR - Authentication BypassPoCCVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunPoCCVE-2022-29383: NETGEAR ProSafe SSL VPN firmware - SQL InjectionPoCCVE-2024-30568: Netgear R6850 V1.1.0.88 - Command InjectionPoCCVE-2024-30569: Netgear R6850 - Information DisclosurePoCCVE-2024-30570: Netgear R6850 - Information DisclosurePoCCVE-2024-57046: Netgear DGN2200 - Improper Authentication