CVE-2023-28337: NETGEAR RAX30 Firmware
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade to complete and bypass certain validation checks. End users can use this to upload modified, unofficial, and potentially malicious firmware to the device.
Affected products
- NETGEAR RAX30 Firmware: any version
Published 2023-03-15. Last modified 2026-06-17.