Netgear warns users to patch auth bypass, XSS router flaws
ID: 3884ede9-8e96-53b7-97cf-d587e8bb6b21
STIX ID: report--3884ede9-8e96-53b7-97cf-d587e8bb6b21
Feed Name: Bleeping Computer
Netgear has issued firmware updates to address two security flaws in select WiFi 6/Nighthawk routers: a stored cross-site scripting (XSS) vulnerability in the XR1000 (fixed in firmware 1.0.0.72, PSV-2023-0122) and an authentication bypass in the CAX30 Nighthawk AX6 cable modem router (fixed in firmware 2.2.2.2, PSV-2023-0138). The advisories warn these bugs could permit session hijacking, unauthorized administrative access, or complete device takeover, and strongly recommend users download and install the latest firmware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
