What happened
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Affected versions
BE9300: before V1.0.1.84 (custom); before V1.1.8.142 (custom); before V1.0.18.164 (custom); before V1.0.5.50 (custom); before V1.2.10.56 (custom); before V1.0.17.142 (custom); before V1.0.14.108 (custom); before V1.0.19.172 (custom); before V6.3.8.11 (custom); before V1.0.1.80 (custom); before V1.0.1.90 (custom) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.