CVE-2023-1327 is a critical authentication bypass vulnerability affecting Netgear RAX30 (AX2400) routers prior to version 1.0.6.74. An unauthenticated attacker can exploit this flaw to reset the administrative password and gain full control over the device's web management interface. With a CVSS score of 9.8, this vulnerability poses a severe risk, allowing for complete compromise of confidentiality, integrity, and availability without requiring user interaction or prior authentication. While no active exploitation or public exploit code has been identified, and community discussion is minimal, the high severity warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.6.74CPE matchmatch criteria | cpe:2.3:o:netgear:rax30_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Authentication Bypass in Netgear RAX30 (AX2400) < 1.0.6.74
Mar 10, 2023Authentication Bypass in Netgear RAX30 (AX2400) < 1.0.6.74
Mar 10, 2023Authentication Bypass in Netgear RAX30 (AX2400) < 1.0.6.74
Mar 10, 2023Authentication Bypass in Netgear RAX30 (AX2400) < 1.0.6.74
Mar 10, 2023