Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-23110 Details

Description

An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification. This affects WNR612v2 Wireless Routers 1.0.0.3 and earlier, DGN1000v3 Modem Router 1.0.0.22 and earlier, D6100 WiFi DSL Modem Routers 1.0.0.63 and earlier, WNR1000v2 Wireless Routers 1.1.2.60 and earlier, XAVN2001v2 Wireless-N Extenders 0.4.0.7 and earlier, WNR2200 Wireless Routers 1.0.1.102 and earlier, WNR2500 Wireless Routers 1.0.0.34 and earlier, R8900 Smart WiFi Routers 1.0.3.6 and earlier, and R9000 Smart WiFi Routers 1.0.3.6 and earlier.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/BkBPIeGco CVEExploitThird Party Advisory
https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/H1lIcXbco CVEExploitThird Party Advisory
https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/HyZRxmb9s CVEExploitThird Party Advisory
https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/r1Z4BX-5i CVEExploitThird Party Advisory
https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/ryjVZz-5s CVEExploitThird Party Advisory

see all 20 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-494Download of Code Without Integrity Check[email protected]
CWE-494Download of Code Without Integrity CheckCISA-ADP

Affected Products

ProductVersions

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-23110
NVD Published Date:
Feb 2, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2023-23110 Details - Not Deferred