CVE-2023-50089: NETGEAR WNR2000 Firmware

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

Affected products

  • NETGEAR WNR2000 Firmware: version 1.0.0.70 only

Published 2023-12-15. Last modified 2026-06-17.