CVE-2023-36499: NETGEAR XR300 Firmware

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.

Affected products

  • NETGEAR XR300 Firmware: version 1.0.3.78 only

Published 2023-08-07. Last modified 2026-06-17.