CVE-2024-23690: NETGEAR FVS336GV2

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interface. An authenticated and remote attacker can execute arbitrary OS commands as root over Telnet by sending crafted "util backup_configuration" commands.

Affected products

  • NETGEAR FVS336GV2: up to and including 4.3.3-6
  • NETGEAR FVS336GV3: up to and including 4.3.5-3

Published 2025-02-04. Last modified 2026-06-17.